Courseiva
Security Operations →mediumMultiple Select

CS0-003 Security Operations Practice Question

A SOC analyst is investigating an alert from Azure Sentinel indicating a user account logged in from an unfamiliar location. The analyst wants to determine if this is a true positive. Which TWO additional log sources should the analyst correlate to make an informed decision?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Activity Logs

Microsoft Entra ID sign-in logs provide authentication details, and Azure Activity Logs provide management plane activity. Correlating these can reveal if the sign-in was part of administrative actions or other anomalies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Security Center alerts

    Why it's wrong here

    Security Center (Defender for Cloud) alerts surface separately-generated detections about resource-level misconfigurations and threats, but they do not contain the authentication event details or resource-management actions needed to corroborate whether this specific sign-in was legitimate.

  • ✗

    Azure Network Watcher flow logs

    Why it's wrong here

    Network Watcher flow logs record layer 3/4 traffic metadata such as source and destination IP, port, and allow/deny decisions at the NSG level, which helps investigate network-based lateral movement but contains no identity or authentication context relevant to validating a user sign-in.

  • ✓

    Azure Activity Logs

    Why this is correct

    Correct. Activity Logs record subscription-level control-plane operations performed by the account after authentication, so correlating them reveals whether the session was used to create, modify, or delete resources, which is a strong indicator of malicious intent versus benign access.

  • ✗

    Azure Key Vault logs

    Why it's wrong here

    Key Vault logs capture secret, key, and certificate access operations specific to that service, which is far narrower than the login investigation at hand; unless the suspicious account is known to interact with Key Vault, this log source offers no relevant corroborating context.

  • ✓

    Microsoft Entra ID sign-in logs

    Why this is correct

    Correct. Microsoft Entra ID sign-in logs contain the authoritative record of the authentication event itself, including source IP, device, conditional access policy results, and MFA status, making them the primary source for confirming or refuting whether the login was anomalous or a true compromise.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.