SC-200 Manage a security operations environment Practice Question
Your organization, Fabrikam, has a hybrid environment with on-premises Active Directory and Microsoft Entra ID. You are using Microsoft Sentinel and Microsoft Defender XDR. You have enabled Microsoft Defender for Identity (MDI) to protect on-premises Active Directory. Recently, you received an incident in Microsoft Sentinel indicating a potential DCSync attack from a domain controller. The incident was generated from an MDI alert. You need to investigate the incident and determine if the attack was successful. You have the following options: A) Use the Microsoft Sentinel incident investigation graph to view entities and relationships. Then query the IdentityDirectoryEvents table for the domain controller to see if any directory replication requests were made. B) Use the Microsoft Defender XDR advanced hunting to query the IdentityLogonEvents table for the domain controller. C) Use the Microsoft Sentinel workbook for MDI to visualize the attack timeline. D) Use the Microsoft Defender for Cloud Apps activity log to review the domain controller's activities. Which option should you choose?
⚠ Common exam trap
Candidates often confuse the IdentityLogonEvents table (logon events) with the IdentityDirectoryEvents table (directory service events), or assume a visualization workbook can replace direct querying for forensic evidence of a DCSync attack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the Microsoft Sentinel incident investigation graph to view entities and relationships. Then query the IdentityDirectoryEvents table for the domain controller to see if any directory replication requests were made.
A DCSync attack involves an attacker impersonating a domain controller to request directory replication via the MS-DRSR protocol. The IdentityDirectoryEvents table in Microsoft Defender for Identity captures directory service replication activities, including the DirectoryReplication request action. Querying this table for the domain controller allows you to confirm if unauthorized replication requests were made, directly indicating a successful DCSync attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the Microsoft Sentinel workbook for MDI to visualize the attack timeline.
Why it's wrong here
The Microsoft Sentinel workbook for MDI provides pre-built visualizations such as alerts and entity timelines, but it is not designed to confirm the specific replication requests that characterize a DCSync attack. A workbook aggregates and charts existing telemetry rather than allowing you to pivot through entities and inspect raw directory replication events from the domain controller. While it may show a macro-level attack timeline, it lacks the granular detail about specific directory replication requests (DS-GetNCChanges) that would confirm DCSync. To verify the attack, you need to query the underlying IdentityDirectoryEvents table rather than rely on workbook visuals.
- ✗
Use the Microsoft Defender XDR advanced hunting to query the IdentityLogonEvents table for the domain controller.
Why it's wrong here
Advanced hunting in Microsoft Defender XDR offers powerful KQL queries, but the IdentityLogonEvents table stores authentication and logon-related events such as sign-in attempts, Kerberos and NTLM authentications, and account changes. A DCSync attack does not generate a logon event; instead, it abuses the Directory Replication Service Remote Protocol (DRSUAPI) to issue GetNCChanges replication requests from a compromised domain controller, which are recorded in the IdentityDirectoryEvents table. Querying IdentityLogonEvents for the domain controller would only reveal interactive or network logons and would miss the replication call entirely. Therefore, while the tool is correct, the chosen table lacks the field and action types needed to detect DCSync.
- ✓
Use the Microsoft Sentinel incident investigation graph to view entities and relationships. Then query the IdentityDirectoryEvents table for the domain controller to see if any directory replication requests were made.
Why this is correct
To confirm the DCSync attack, first open the incident investigation graph to see how the compromised entity relates to the domain controller and other machines. Then query the IdentityDirectoryEvents table for the domain controller, filtering on action types that correspond to directory replication, such as the GetNCChanges operation. This table, sourced from Microsoft Defender for Identity, records replication requests and is exactly the data required to prove that an account attempted to replicate credentials from the domain controller. The investigation graph guides you to the right entity (the DC) and shows the attack path, while the IdentityDirectoryEvents query provides the forensic evidence.
- ✗
Use the Microsoft Defender for Cloud Apps activity log to review the domain controller's activities.
Why it's wrong here
Microsoft Defender for Cloud Apps (formerly MCAS) monitors activity across cloud applications like Office 365, Salesforce, and AWS; it does not ingest on-premises Active Directory or domain controller telemetry. DCSync replicates directory data directly between on-prem domain controllers using DRSUAPI, leaving traces only in Windows event logs like 4662 and in Microsoft Defender for Identity's IdentityDirectoryEvents. Thus, reviewing the Defender for Cloud Apps activity log would show SaaS sessions and app usage but cannot reveal any on-prem directory replication requests. To detect DCSync, you must use directory-centric telemetry from MDI or domain controller security logs, not cloud app audit logs.
Visual reference
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.