Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

You are hunting for signs of credential dumping using Mimikatz. Which process events in Microsoft Defender for Endpoint would most likely indicate this activity?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A process opening lsass.exe with access to process memory (e.g., PROCESS_VM_READ)

Mimikatz typically opens lsass.exe with specific access permissions like PROCESS_VM_READ to read process memory and dump credentials. Options B, C, and D are not specific indicators: PowerShell making network connections is too broad, svchost spawning from explorer is a normal pattern, and cmd executing whoami is not credential dumping.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A process opening lsass.exe with access to process memory (e.g., PROCESS_VM_READ)

    Why this is correct

    Mimikatz reads credential material directly from LSASS memory, so a process requesting PROCESS_VM_READ against lsass.exe is the strongest signal. Legitimate tools rarely open LSASS with memory-read rights, making this access mask the specific indicator Microsoft Defender for Endpoint surfaces for credential-dumping detection.

  • ✗

    A process named powershell.exe making network connections to an external IP

    Why it's wrong here

    powershell.exe making external network connections suggests command-and-control or download activity, not credential dumping. Mimikatz operates locally against LSASS memory, so outbound connections are not the primary indicator. This is tempting because PowerShell is commonly abused in attacks, but the network connection axis does not align with credential theft.

  • ✗

    A process named svchost.exe spawning from explorer.exe

    Why it's wrong here

    svchost.exe spawning from explorer.exe indicates a service host launched by user shell activity, not credential dumping. Mimikatz typically appears as lsass.exe access or suspicious process injection. This pattern is tempting because unusual parent-child relationships can signal malware, but it does not match the LSASS memory access characteristic of credential dumping.

  • ✗

    A process named cmd.exe executing whoami

    Why it's wrong here

    cmd.exe executing whoami is routine reconnaissance, not credential dumping. Mimikatz targets LSASS process memory to extract credentials, producing events such as lsass.exe handle access or suspicious modules. This is tempting because whoami often follows privilege escalation, but it does not demonstrate credential extraction.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.