Courseiva
Perform threat hunting →hardMultiple Choice

SC-200 Perform threat hunting Practice Question

You are hunting for signs of Kerberoasting in Microsoft Sentinel. Which hunting query using KQL would you use to identify service principal names (SPNs) being queried via Kerberos TGS requests?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SecurityEvent | where EventID == 4769 and TicketEncryptionType == 0x17

Kerberoasting involves requesting TGS tickets for Service Principal Names (SPNs). In Microsoft Sentinel, the SecurityEvent table with EventID 4769 logs TGS requests. TicketEncryptionType 0x17 indicates RC4 encryption, which is commonly used in Kerberoasting attacks. Option A correctly identifies this query. Option D is incorrect because EventID 4768 is for TGT requests, not TGS. Option B (DeviceEvents) may not capture this specific event, and Option C (DeviceLogonEvents) does not focus on SPN details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SecurityEvent | where EventID == 4769 and TicketEncryptionType == 0x17

    Why this is correct

    Event ID 4769 logs Kerberos service ticket (TGS) requests, and encryption type 0x17 (RC4-HMAC) reveals weak cipher use typical of Kerberoasting, where attackers request SPN tickets then crack them offline. Filtering both fields surfaces exactly the SPN queries the stem requires.

  • ✗

    DeviceEvents | where ActionType == 'KerberosTicketRequest'

    Why it's wrong here

    DeviceEvents does not expose a KerberosTicketRequest ActionType; that table covers endpoint telemetry such as process and file events, not Kerberos ticket operations. It would be the correct source for detecting credential theft or suspicious process execution on endpoints, not SPN enumeration via TGS requests.

  • ✗

    DeviceLogonEvents | where LogonType == 'Kerberos' and AccountDomain == 'Service'

    Why it's wrong here

    DeviceLogonEvents records interactive and network logons with LogonType values like Interactive or RemoteInteractive; 'Kerberos' is not a valid LogonType, and AccountDomain 'Service' is not a real domain. This table suits investigating suspicious sign-ins, not Kerberos TGS ticket requests for SPNs.

  • ✗

    SecurityEvent | where EventID == 4768 and TicketEncryptionType == 0x17

    Why it's wrong here

    Event ID 4768 is a Kerberos authentication ticket (TGT) request, and 0x17 denotes RC4 encryption; Kerberoasting is identified through TGS requests, logged as Event ID 4769. TGT issuance queries would be the right focus when hunting for AS-REP roasting or weak encryption during initial authentication.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.