Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

Your organization uses Microsoft Sentinel with custom analytics rules. During a threat hunt, you want to identify lateral movement using pass-the-hash techniques. Which data source combination is most effective?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows Security Event ID 4624 (Logon) with LogonType 3 and NTLM attributes

Windows Security Event ID 4624 with LogonType 3 (network logon) and NTLM authentication attributes are key indicators of pass-the-hash attacks, as NTLM is the protocol typically exploited. Option A is wrong because Microsoft Entra ID sign-in logs only cover cloud authentication, not on-premises lateral movement. Option B is wrong because DeviceEvents and DeviceLogonEvents from Microsoft Defender for Endpoint focus on endpoint behavior and do not provide the detailed NTLM attributes needed. Option C is wrong because Sysmon Event ID 3 and Windows Firewall logs capture network connections, not authentication details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra ID sign-in logs and Office 365 audit logs

    Why it's wrong here

    Microsoft Entra ID sign-in logs record authentication to cloud services, not on-premises Windows logons. They capture interactive and non-interactive sign-ins with Microsoft Entra ID tokens, but NTLM pass-the-hash events occur on domain controllers and servers using on-premise Active Directory. Similarly, Office 365 audit logs track mailbox and document activities, lacking the security event ID 4624 details. Hence these sources won't reveal NTLM authentication attempts.

  • ✗

    DeviceEvents and DeviceLogonEvents from Microsoft Defender for Endpoint

    Why it's wrong here

    While DeviceLogonEvents from Defender for Endpoint can log local logons, it primarily reports device-level activities and may not include the full NTLM authentication package or logon sub-status details needed to identify pass-the-hash. SecurityEvent, which ingests Windows Security event logs from your on-premises infrastructure, provides Event 4624 with granular fields like AuthenticationPackageName, LogonType, and impersonation levels. Additionally, not all on-premises devices may have MDE telemetry forwarded to Sentinel, making SecurityEvent a more reliable source for this detection.

  • ✗

    Sysmon Event ID 3 (Network connect) and Windows Firewall logs

    Why it's wrong here

    Sysmon Event ID 3 logs network connections, including source/destination IPs and process IDs, but it omits the authentication method used for that connection. Windows Firewall logs similarly show allowed/blocked traffic without indicating whether NTLM was the authentication protocol. Pass-the-hash attacks require observing the logon event itself, not just the network flow, so these sources cannot conclusively detect the attack and would need to be correlated with Event 4624.

  • ✓

    Windows Security Event ID 4624 (Logon) with LogonType 3 and NTLM attributes

    Why this is correct

    Event 4624 with LogonType 3 and authentication package NTLM indicates a network logon using NTLM, which is exactly what a pass-the-hash attack performs. The logon process NtLmSsp and the authentication package NTLM in the event are key indicators; LogonType 3 signifies remote access to a resource. While normal network shares also create such events, filtering for unusual source workstations or privileged accounts can reveal pass-the-hash activity. This is the most direct Windows Security log source for detecting NTLM-based lateral movement.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.