SC-200 Perform threat hunting • Set 8
SC-200 Perform threat hunting Practice Test 8 — 15 questions with explanations. Free, no signup.
You are a security analyst at a company using Microsoft Sentinel. You have been asked to perform a threat hunt to identify potential brute-force attacks against your on-premises Active Directory. The relevant data is ingested into Sentinel from Windows Event Logs (Event ID 4625) and Azure ATP (now Microsoft Defender for Identity). Your hunting query should focus on failed logon attempts with high frequency from the same source IP within a short time window. You need to write a KQL query that returns the top 10 source IPs with the most failed logon attempts in the last 24 hours. Which KQL query should you use?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.