SC-200 Perform threat hunting Practice Question
You are hunting for signs of Kerberoasting in Microsoft Sentinel. Which hunting query using KQL would you use to identify service principal names (SPNs) being queried via Kerberos TGS requests?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SecurityEvent | where EventID == 4769 and TicketEncryptionType == 0x17
Kerberoasting involves requesting TGS tickets for Service Principal Names (SPNs). In Microsoft Sentinel, the SecurityEvent table with EventID 4769 logs TGS requests. TicketEncryptionType 0x17 indicates RC4 encryption, which is commonly used in Kerberoasting attacks. Option A correctly identifies this query. Option D is incorrect because EventID 4768 is for TGT requests, not TGS. Option B (DeviceEvents) may not capture this specific event, and Option C (DeviceLogonEvents) does not focus on SPN details.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SecurityEvent | where EventID == 4769 and TicketEncryptionType == 0x17
Why this is correct
Event ID 4769 logs Kerberos service ticket (TGS) requests, and encryption type 0x17 (RC4-HMAC) reveals weak cipher use typical of Kerberoasting, where attackers request SPN tickets then crack them offline. Filtering both fields surfaces exactly the SPN queries the stem requires.
- ✗
DeviceEvents | where ActionType == 'KerberosTicketRequest'
Why it's wrong here
DeviceEvents does not expose a KerberosTicketRequest ActionType; that table covers endpoint telemetry such as process and file events, not Kerberos ticket operations. It would be the correct source for detecting credential theft or suspicious process execution on endpoints, not SPN enumeration via TGS requests.
- ✗
DeviceLogonEvents | where LogonType == 'Kerberos' and AccountDomain == 'Service'
Why it's wrong here
DeviceLogonEvents records interactive and network logons with LogonType values like Interactive or RemoteInteractive; 'Kerberos' is not a valid LogonType, and AccountDomain 'Service' is not a real domain. This table suits investigating suspicious sign-ins, not Kerberos TGS ticket requests for SPNs.
- ✗
SecurityEvent | where EventID == 4768 and TicketEncryptionType == 0x17
Why it's wrong here
Event ID 4768 is a Kerberos authentication ticket (TGT) request, and 0x17 denotes RC4 encryption; Kerberoasting is identified through TGS requests, logged as Event ID 4769. TGT issuance queries would be the right focus when hunting for AS-REP roasting or weak encryption during initial authentication.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.