CS0-003 Security Operations Practice Question
A security analyst is reviewing an alert from Azure Sentinel that indicates a possible privilege escalation attempt. The alert is based on a correlation rule that detects unusual usage of the 'Add-AzKeyVaultKey' cmdlet by a user who has never used it before. The analyst needs to validate the alert and determine if the activity is malicious. Which THREE actions should the analyst take?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the user's role assignments and permissions
Checking Microsoft Entra ID logs for the authentication context, reviewing the user's recent activity history, and examining the Key Vault audit logs for any subsequent access are all relevant steps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Check the user's role assignments and permissions
Why this is correct
Checking the user's RBAC role assignments against Key Vault establishes whether Add-AzKeyVaultKey was actually within that person's authorized scope of duties, since a first-time use of a cmdlet by someone who legitimately holds a Key Vault Contributor or Crypto Officer role is far less suspicious than the same call from an account with no assigned Key Vault permissions.
- ✗
Run a vulnerability scan on the user's workstation
Why it's wrong here
Scanning the endpoint for OS or application vulnerabilities addresses local exploit exposure, but it does nothing to confirm whether this specific Azure Resource Manager API call was authorized or malicious, making it the wrong triage step for validating a cloud control-plane alert.
- ✓
Review the Key Vault's diagnostic logs for any key retrieval after the cmdlet
Why this is correct
Examining Key Vault diagnostic logs for subsequent key or secret retrieval operations reveals whether the newly added key was actually used to decrypt data or exfiltrate secrets, turning a single suspicious cmdlet event into evidence of a broader attack chain if follow-on access occurred.
- ✗
Disable the user account immediately
Why it's wrong here
Immediately disabling the account skips the investigative steps needed to confirm malicious intent and risks halting a legitimate administrator's authorized key-rotation task, which can trigger a business disruption; containment should follow validation, not precede it, unless active compromise is already confirmed.
- ✓
Verify the user's identity by checking Microsoft Entra ID sign-in logs
Why this is correct
Pulling Microsoft Entra ID sign-in logs for the account shows the source IP, device compliance state, and conditional access result at the time of the cmdlet execution, which lets the analyst determine whether the session originated from a recognized corporate location or from an anomalous geography suggesting credential compromise.
Go deeper
Related to this question
Learn chapter
OWASP Top 10 for Security Analysts
Key term
Azure Sentinel
Azure Sentinel is Microsoft's cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) service that uses intelligent analytics to help protect an enterprise's entire digital estate.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.