CS0-003 Security Operations Practice Question
A SOC analyst is investigating an alert from Azure Sentinel indicating a user account logged in from an unfamiliar location. The analyst wants to determine if this is a true positive. Which TWO additional log sources should the analyst correlate to make an informed decision?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Activity Logs
Microsoft Entra ID sign-in logs provide authentication details, and Azure Activity Logs provide management plane activity. Correlating these can reveal if the sign-in was part of administrative actions or other anomalies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Security Center alerts
Why it's wrong here
Security Center (Defender for Cloud) alerts surface separately-generated detections about resource-level misconfigurations and threats, but they do not contain the authentication event details or resource-management actions needed to corroborate whether this specific sign-in was legitimate.
- ✗
Azure Network Watcher flow logs
Why it's wrong here
Network Watcher flow logs record layer 3/4 traffic metadata such as source and destination IP, port, and allow/deny decisions at the NSG level, which helps investigate network-based lateral movement but contains no identity or authentication context relevant to validating a user sign-in.
- ✓
Azure Activity Logs
Why this is correct
Correct. Activity Logs record subscription-level control-plane operations performed by the account after authentication, so correlating them reveals whether the session was used to create, modify, or delete resources, which is a strong indicator of malicious intent versus benign access.
- ✗
Azure Key Vault logs
Why it's wrong here
Key Vault logs capture secret, key, and certificate access operations specific to that service, which is far narrower than the login investigation at hand; unless the suspicious account is known to interact with Key Vault, this log source offers no relevant corroborating context.
- ✓
Microsoft Entra ID sign-in logs
Why this is correct
Correct. Microsoft Entra ID sign-in logs contain the authoritative record of the authentication event itself, including source IP, device, conditional access policy results, and MFA status, making them the primary source for confirming or refuting whether the login was anomalous or a true compromise.
Go deeper
Related to this question
Learn chapter
User and Entity Behaviour Analytics (UEBA)
Key term
True positive
A true positive is when a security tool correctly identifies a real threat or malicious activity.
Key term
Azure Sentinel
Azure Sentinel is Microsoft's cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) service that uses intelligent analytics to help protect an enterprise's entire digital estate.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.