SC-200 Perform threat hunting Practice Question
Your organization uses Microsoft Defender for Endpoint and Microsoft Sentinel. As part of a threat hunting exercise, you need to detect potential lateral movement using remote desktop protocol (RDP). You want to identify devices that have initiated multiple RDP connections to different internal IP addresses within a short time frame. Which hunting query should you use in Microsoft Sentinel's Log Analytics workspace?
⚠ Common exam trap
SC-200 often tests whether candidates know which Defender for Endpoint advanced hunting table contains network connection metadata versus process or identity data — picking DeviceProcessEvents or IdentityLogonEvents instead of DeviceNetworkEvents is the classic mistake.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents | where RemotePort == 3389 and ActionType == 'ConnectionSuccess' | summarize dcount(RemoteIP) by DeviceName
DeviceNetworkEvents is the Microsoft Defender for Endpoint table that records network connection telemetry, including the RemotePort and ActionType fields. Filtering on RemotePort == 3389 (the RDP port) with ActionType == 'ConnectionSuccess' and then using dcount(RemoteIP) by DeviceName surfaces devices that successfully connected to many distinct internal IPs — the classic signature of RDP-based lateral movement. This is the query pattern Microsoft recommends in Sentinel hunting workbooks for detecting RDP fan-out behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Syslog | where Facility == 'auth' and Message contains 'RDP' | summarize count() by HostName
Why it's wrong here
Syslog captures Linux syslog messages and is not used for Windows RDP network connections. It does not record RDP connection attempts to multiple IPs.
- ✗
DeviceProcessEvents | where ProcessCommandLine contains 'mstsc.exe' | summarize count() by DeviceName
Why it's wrong here
DeviceProcessEvents logs process creation events, such as running mstsc.exe, but does not show the network connections made by that process. It cannot identify multiple distinct destination IPs.
- ✓
DeviceNetworkEvents | where RemotePort == 3389 and ActionType == 'ConnectionSuccess' | summarize dcount(RemoteIP) by DeviceName
Why this is correct
DeviceNetworkEvents with RemotePort 3389 and ActionType 'ConnectionSuccess' captures successful RDP sessions, and summarising dcount(RemoteIP) by DeviceName surfaces devices connecting to many distinct internal addresses — exactly the fan-out pattern the stem's lateral movement hunt requires.
- ✗
IdentityLogonEvents | where LogonType == 'RemoteInteractive' | summarize dcount(IPAddress) by DeviceName
Why it's wrong here
IdentityLogonEvents records authentication logon events, such as RemoteInteractive logons, but not the network connections themselves. It cannot show the destination IPs of RDP connections.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.