SC-200 Perform threat hunting Practice Question
You are building a threat hunting query in Microsoft Sentinel to detect potential lateral movement via Windows Management Instrumentation (WMI). You want to identify processes that were created remotely using WMI, which often indicates an attacker moving laterally. Which two data sources or fields should you use in your query to detect this activity? (Choose two.)
⚠ Common exam trap
The trap here is assuming that network connections to port 135 or generic network logons are sufficient to detect WMI lateral movement, when only process-level events tied to WMI can confirm remote process creation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceEvents with ActionType == 'WmiProcessCreate'
To detect WMI-based lateral movement, you need process creation events where the parent is wmiprvse.exe (indicating WMI spawned the process) or events explicitly logged as WmiProcessCreate. DeviceProcessEvents with InitiatingProcessFileName 'wmiprvse.exe' and DeviceEvents with ActionType 'WmiProcessCreate' both directly capture this behavior. Other sources like network events or logon events are too generic and do not confirm WMI process execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceEvents with ActionType == 'WmiProcessCreate'
Why this is correct
DeviceEvents includes various event types, and the ActionType 'WmiProcessCreate' specifically logs process creation via WMI. This is a direct signal of WMI-based process execution, which is exactly what you need to detect lateral movement. Querying DeviceEvents for this action type will surface relevant events without relying on parent process inference.
- ✓
DeviceProcessEvents with InitiatingProcessFileName == 'wmiprvse.exe'
Why this is correct
DeviceProcessEvents captures process creation events. When WMI is used to create a process remotely, the parent process is often wmiprvse.exe (WMI Provider Host). Filtering for InitiatingProcessFileName equal to 'wmiprvse.exe' can reveal processes spawned by WMI, which is a strong indicator of remote process creation via WMI, a common lateral movement technique.
- ✗
DeviceRegistryEvents with RegistryKey contains 'WMI'
Why it's wrong here
DeviceRegistryEvents tracks registry modifications. While WMI persistence might involve registry keys, the scenario is about detecting process creation via WMI for lateral movement, not persistence. Registry events would not directly show a remote process creation event. Thus, this is not an appropriate data source for this specific hunt.
- ✗
DeviceNetworkEvents with RemotePort == 135
Why it's wrong here
DeviceNetworkEvents with RemotePort 135 would show connections to the RPC endpoint mapper, which is used by WMI and other RPC services. However, it does not confirm that a process was created via WMI; it only indicates potential RPC communication. Many legitimate activities use port 135, so this alone is not a reliable indicator of WMI lateral movement.
- ✗
DeviceLogonEvents with LogonType == 3
Why it's wrong here
DeviceLogonEvents with LogonType 3 (network logon) can indicate lateral movement, but it is not specific to WMI. Many protocols use network logons, so this would generate false positives. The question asks for WMI-based process creation detection, and logon events do not provide the necessary process-level detail.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.