Courseiva
easyMultiple ChoiceObjective-mapped

SC-100 Practice Question: A SOC analyst needs to investigate a potential…

A SOC analyst needs to investigate a potential privilege escalation using Azure AD roles. Which Microsoft 365 Defender data source would be most useful to review?

⚠ Common exam trap

Microsoft often tests the distinction between Azure AD audit logs (which track directory configuration changes like role assignments) and Microsoft 365 audit logs (which track user activity across workloads), leading candidates to mistakenly choose the broader Microsoft 365 audit logs when the question specifically targets Azure AD role changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Azure Active Directory audit logs

Azure AD audit logs (now part of the Azure Monitor / Microsoft Entra audit logs) are the authoritative source for tracking changes to Azure AD roles, including role assignments, activations of Privileged Identity Management (PIM) roles, and modifications to directory roles. Since the question specifically involves privilege escalation using Azure AD roles, these logs contain the necessary details such as who assigned a role, when, and from which IP address, making them the most directly relevant data source.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft 365 Defender identity logs

    Why it's wrong here

    Microsoft 365 Defender does not maintain a separate identity-log repository; its identity-related detections (e.g., from Microsoft Defender for Identity) are built on telemetry derived from Azure AD and domain controllers. For privilege-escalation investigations, Azure AD audit logs are the authoritative record of role assignments and permission changes, not Defender's aggregated alert outputs or signals.

  • Azure Active Directory audit logs

    Why this is correct

    Azure AD audit logs (now part of Microsoft Entra ID) provide a comprehensive, immutable record of directory events, including role assignments, role activations, and permission changes. These logs precisely capture the actor, target, timestamp, and metadata for every privilege-modification action, making them the definitive source for tracing how a user acquired elevated rights or escalated privileges.

  • Microsoft Defender for Cloud Apps logs

    Why it's wrong here

    Microsoft Defender for Cloud Apps (MDA) focuses on behavioral analytics for cloud applications, such as sign-in risk, impossible travel, and file-sharing anomalies. While it can surface suspicious activity that might accompany privilege escalation, it does not log directory-level role assignments or permission modifications; those changes are only recorded in Azure AD audit logs with full fidelity.

  • Microsoft 365 audit logs

    Why it's wrong here

    Microsoft 365 audit logs aggregate events from workloads like Exchange, SharePoint, and Teams via the unified audit log, and may include some user sign-in events, but they do not capture the complete set of Azure AD directory changes. Role assignments, especially via Privileged Identity Management, produce detailed entries solely in Azure AD audit logs, making that the correct log source for a privilege-escalation inquiry.

About these practice questions

One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.