SC-200 Perform threat hunting Practice Question
You are hunting for lateral movement in your environment. In Microsoft Defender for Identity, which activity is a strong indicator of a potential pass-the-hash attack?
⚠ Common exam trap
SC-200 often tests the specific indicators of pass-the-hash, and candidates may confuse it with other suspicious activities like service account logons or smart card usage. The trap is selecting a common but non-specific event instead of the NTLM authentication from an unusual machine.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An NTLM authentication originating from a machine that is not the user's usual machine.
Pass-the-hash attacks involve using a captured NTLM hash to authenticate without knowing the plaintext password. In Defender for Identity, a strong indicator is NTLM authentication originating from a machine that is not the user's usual machine, because the attacker is moving laterally using the hash from a compromised host. This behavior is flagged as suspicious because it deviates from normal user logon patterns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A user logging on with a smart card.
Why it's wrong here
Smart card logon is an authentication method that uses a physical token and PIN, where the private key resides on the card and never leaves it. Since an attacker who has compromised a password or NTLM hash cannot easily obtain the private key, smart card authentication is generally considered secure. A smart card logon from a user's normal workstation is a routine and benign event, and even an anomalous smart card logon would require physical possession of the token, making it a weak indicator of lateral movement.
- ✓
An NTLM authentication originating from a machine that is not the user's usual machine.
Why this is correct
NTLM authentication originating from a machine the user does not normally use is a strong lateral movement indicator because NTLM uses a password hash in a challenge-response protocol, and attackers often employ pass-the-hash techniques to authenticate from a compromised host. In a Windows environment, this would appear as Event ID 4624 with LogonType 3 and NTLM as the authentication package, combined with a source hostname or IP that violates the user's typical logon pattern. This aligns with stolen credentials or hash theft, as a legitimate user would almost always authenticate from their known workstations or VPN exit points, so an unexpected source machine is statistically suspicious.
- ✗
A remote desktop connection from a non-admin workstation to a domain controller.
Why it's wrong here
An RDP session from a non-admin workstation to a domain controller is unusual but not conclusive evidence of lateral movement because domain administrators often initiate remote desktop connections from lower-privileged machines to manage servers. RDP is a common administrative tool, and a single connection may be benign unless accompanied by other malicious activities like credential dumping, scheduled task creation, or service modifications. Additionally, RDP could be a legitimate support action or a jump host, so this indicator requires correlation with additional telemetry such as process call trees and accounts with elevated privileges before treating it as a high-confidence threat signal.
- ✗
A service account logging on to multiple servers simultaneously.
Why it's wrong here
A service account authenticating to multiple servers at the same time is typical of normal operations because service accounts are specifically designed to run scheduled tasks, services, and batch jobs across a fleet of hosts. In a healthy environment, a single service account can generate simultaneous network logons (LogonType 3) to dozens of servers without any malicious intent. To identify lateral movement, an analyst would need to compare this behavior against a baseline of that account's usual hosts, times, and logon types, looking for sudden changes or interactive logons (LogonType 2 or 10) that could signal account misuse, rather than flagging multi-server network logons outright.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.