SC-200 Perform threat hunting Practice Question
You are hunting for signs of credential dumping using Mimikatz. Which process events in Microsoft Defender for Endpoint would most likely indicate this activity?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A process opening lsass.exe with access to process memory (e.g., PROCESS_VM_READ)
Mimikatz typically opens lsass.exe with specific access permissions like PROCESS_VM_READ to read process memory and dump credentials. Options B, C, and D are not specific indicators: PowerShell making network connections is too broad, svchost spawning from explorer is a normal pattern, and cmd executing whoami is not credential dumping.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A process opening lsass.exe with access to process memory (e.g., PROCESS_VM_READ)
Why this is correct
Mimikatz reads credential material directly from LSASS memory, so a process requesting PROCESS_VM_READ against lsass.exe is the strongest signal. Legitimate tools rarely open LSASS with memory-read rights, making this access mask the specific indicator Microsoft Defender for Endpoint surfaces for credential-dumping detection.
- ✗
A process named powershell.exe making network connections to an external IP
Why it's wrong here
powershell.exe making external network connections suggests command-and-control or download activity, not credential dumping. Mimikatz operates locally against LSASS memory, so outbound connections are not the primary indicator. This is tempting because PowerShell is commonly abused in attacks, but the network connection axis does not align with credential theft.
- ✗
A process named svchost.exe spawning from explorer.exe
Why it's wrong here
svchost.exe spawning from explorer.exe indicates a service host launched by user shell activity, not credential dumping. Mimikatz typically appears as lsass.exe access or suspicious process injection. This pattern is tempting because unusual parent-child relationships can signal malware, but it does not match the LSASS memory access characteristic of credential dumping.
- ✗
A process named cmd.exe executing whoami
Why it's wrong here
cmd.exe executing whoami is routine reconnaissance, not credential dumping. Mimikatz targets LSASS process memory to extract credentials, producing events such as lsass.exe handle access or suspicious modules. This is tempting because whoami often follows privilege escalation, but it does not demonstrate credential extraction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.