Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

Your organization uses Microsoft Defender for Endpoint and Microsoft Sentinel. As part of a threat hunting exercise, you need to detect potential lateral movement using remote desktop protocol (RDP). You want to identify devices that have initiated multiple RDP connections to different internal IP addresses within a short time frame. Which hunting query should you use in Microsoft Sentinel's Log Analytics workspace?

⚠ Common exam trap

SC-200 often tests whether candidates know which Defender for Endpoint advanced hunting table contains network connection metadata versus process or identity data — picking DeviceProcessEvents or IdentityLogonEvents instead of DeviceNetworkEvents is the classic mistake.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents | where RemotePort == 3389 and ActionType == 'ConnectionSuccess' | summarize dcount(RemoteIP) by DeviceName

DeviceNetworkEvents is the Microsoft Defender for Endpoint table that records network connection telemetry, including the RemotePort and ActionType fields. Filtering on RemotePort == 3389 (the RDP port) with ActionType == 'ConnectionSuccess' and then using dcount(RemoteIP) by DeviceName surfaces devices that successfully connected to many distinct internal IPs — the classic signature of RDP-based lateral movement. This is the query pattern Microsoft recommends in Sentinel hunting workbooks for detecting RDP fan-out behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Syslog | where Facility == 'auth' and Message contains 'RDP' | summarize count() by HostName

    Why it's wrong here

    Syslog captures Linux syslog messages and is not used for Windows RDP network connections. It does not record RDP connection attempts to multiple IPs.

  • ✗

    DeviceProcessEvents | where ProcessCommandLine contains 'mstsc.exe' | summarize count() by DeviceName

    Why it's wrong here

    DeviceProcessEvents logs process creation events, such as running mstsc.exe, but does not show the network connections made by that process. It cannot identify multiple distinct destination IPs.

  • ✓

    DeviceNetworkEvents | where RemotePort == 3389 and ActionType == 'ConnectionSuccess' | summarize dcount(RemoteIP) by DeviceName

    Why this is correct

    DeviceNetworkEvents with RemotePort 3389 and ActionType 'ConnectionSuccess' captures successful RDP sessions, and summarising dcount(RemoteIP) by DeviceName surfaces devices connecting to many distinct internal addresses — exactly the fan-out pattern the stem's lateral movement hunt requires.

  • ✗

    IdentityLogonEvents | where LogonType == 'RemoteInteractive' | summarize dcount(IPAddress) by DeviceName

    Why it's wrong here

    IdentityLogonEvents records authentication logon events, such as RemoteInteractive logons, but not the network connections themselves. It cannot show the destination IPs of RDP connections.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.