SC-200 Perform threat hunting Practice Question
Your organization uses Microsoft Sentinel with custom analytics rules. During a threat hunt, you want to identify lateral movement using pass-the-hash techniques. Which data source combination is most effective?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Security Event ID 4624 (Logon) with LogonType 3 and NTLM attributes
Windows Security Event ID 4624 with LogonType 3 (network logon) and NTLM authentication attributes are key indicators of pass-the-hash attacks, as NTLM is the protocol typically exploited. Option A is wrong because Microsoft Entra ID sign-in logs only cover cloud authentication, not on-premises lateral movement. Option B is wrong because DeviceEvents and DeviceLogonEvents from Microsoft Defender for Endpoint focus on endpoint behavior and do not provide the detailed NTLM attributes needed. Option C is wrong because Sysmon Event ID 3 and Windows Firewall logs capture network connections, not authentication details.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID sign-in logs and Office 365 audit logs
Why it's wrong here
Microsoft Entra ID sign-in logs record authentication to cloud services, not on-premises Windows logons. They capture interactive and non-interactive sign-ins with Microsoft Entra ID tokens, but NTLM pass-the-hash events occur on domain controllers and servers using on-premise Active Directory. Similarly, Office 365 audit logs track mailbox and document activities, lacking the security event ID 4624 details. Hence these sources won't reveal NTLM authentication attempts.
- ✗
DeviceEvents and DeviceLogonEvents from Microsoft Defender for Endpoint
Why it's wrong here
While DeviceLogonEvents from Defender for Endpoint can log local logons, it primarily reports device-level activities and may not include the full NTLM authentication package or logon sub-status details needed to identify pass-the-hash. SecurityEvent, which ingests Windows Security event logs from your on-premises infrastructure, provides Event 4624 with granular fields like AuthenticationPackageName, LogonType, and impersonation levels. Additionally, not all on-premises devices may have MDE telemetry forwarded to Sentinel, making SecurityEvent a more reliable source for this detection.
- ✗
Sysmon Event ID 3 (Network connect) and Windows Firewall logs
Why it's wrong here
Sysmon Event ID 3 logs network connections, including source/destination IPs and process IDs, but it omits the authentication method used for that connection. Windows Firewall logs similarly show allowed/blocked traffic without indicating whether NTLM was the authentication protocol. Pass-the-hash attacks require observing the logon event itself, not just the network flow, so these sources cannot conclusively detect the attack and would need to be correlated with Event 4624.
- ✓
Windows Security Event ID 4624 (Logon) with LogonType 3 and NTLM attributes
Why this is correct
Event 4624 with LogonType 3 and authentication package NTLM indicates a network logon using NTLM, which is exactly what a pass-the-hash attack performs. The logon process NtLmSsp and the authentication package NTLM in the event are key indicators; LogonType 3 signifies remote access to a resource. While normal network shares also create such events, filtering for unusual source workstations or privileged accounts can reveal pass-the-hash activity. This is the most direct Windows Security log source for detecting NTLM-based lateral movement.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.