Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Identity. The security team wants to monitor for suspected DCSync attacks. Which Windows Event ID should you monitor to detect DCSync activity?

⚠ Common exam trap

Test-takers frequently confuse authentication events (4776, 4624) or credential use events (4648) with the directory replication operation that DCSync actually performs, leading them to choose a logon-related event ID instead of the object access event that captures the replication request.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Event ID 4662: An operation was performed on an object.

Event ID 4662 logs any operation performed on an Active Directory object, including the directory service access control entry for the DS-Replication-Get-Changes-All extended right (control access right 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2). A DCSync attack uses this right to replicate domain credentials from a domain controller, so monitoring 4662 with the specific object type and access mask for replication is the correct detection method.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Event ID 4776: The domain controller attempted to validate the credentials for an account.

    Why it's wrong here

    Event ID 4776 is generated when a domain controller validates credentials for an account, typically for NTLM or other authentication attempts. It records the authentication attempt itself, not any subsequent directory service operations. DCSync abuse relies on the Directory Replication Service Remote Protocol (MS-DRSR) to replicate password hashes, which would be logged as directory object operations, not credential validation. Therefore, 4776 is unrelated to detecting the replication request that characterizes a DCSync attack.

  • ✓

    Event ID 4662: An operation was performed on an object.

    Why this is correct

    Event ID 4662 logs when an operation is performed on an Active Directory object, including directory replication operations. In the context of DCSync, you would look for 4662 events where the operation includes control access rights like DS-Replication-Get-Changes or DS-Replication-Get-Changes-All. These rights are required to perform replication and, when requested from a non-domain-controller source, are a strong indicator of a DCSync attempt. This makes 4662 the correct event to monitor for this attack.

  • ✗

    Event ID 4648: A logon was attempted using explicit credentials.

    Why it's wrong here

    Event ID 4648 records when a user attempts a logon using explicit credentials, such as with the 'runas' command or secondary logon services. While this event can reveal credential usage, it does not indicate what services or operations were accessed after authentication. DCSync attacks do not require explicit credential logon; instead, they leverage an established session with an account that has replication privileges. The replication request itself is logged as a directory object operation (4662), not as a logon event, so 4648 is not the appropriate event for DCSync detection.

  • ✗

    Event ID 4624: An account was successfully logged on.

    Why it's wrong here

    Event ID 4624 indicates that a user successfully logged onto a system, which is a generic event that occurs for any normal authentication. The event only confirms that authentication succeeded; it does not capture post-logon activity such as directory replication. DCSync attacks are performed over a replication protocol after authentication, and the replication request is what needs to be monitored, typically via 4662. Since 4624 carries no information about the replication operation, it is not suitable for identifying DCSync attempts.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.