easyMultiple ChoiceObjective-mapped
SC-100 Practice Question: A SOC analyst needs to investigate a potential…
A SOC analyst needs to investigate a potential privilege escalation using Azure AD roles. Which Microsoft 365 Defender data source would be most useful to review?
⚠ Common exam trap
Microsoft often tests the distinction between Azure AD audit logs (which track directory configuration changes like role assignments) and Microsoft 365 audit logs (which track user activity across workloads), leading candidates to mistakenly choose the broader Microsoft 365 audit logs when the question specifically targets Azure AD role changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Active Directory audit logs
Azure AD audit logs (now part of the Azure Monitor / Microsoft Entra audit logs) are the authoritative source for tracking changes to Azure AD roles, including role assignments, activations of Privileged Identity Management (PIM) roles, and modifications to directory roles. Since the question specifically involves privilege escalation using Azure AD roles, these logs contain the necessary details such as who assigned a role, when, and from which IP address, making them the most directly relevant data source.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft 365 Defender identity logs
Why it's wrong here
Microsoft 365 Defender does not maintain a separate identity-log repository; its identity-related detections (e.g., from Microsoft Defender for Identity) are built on telemetry derived from Azure AD and domain controllers. For privilege-escalation investigations, Azure AD audit logs are the authoritative record of role assignments and permission changes, not Defender's aggregated alert outputs or signals.
- ✓
Azure Active Directory audit logs
Why this is correct
Azure AD audit logs (now part of Microsoft Entra ID) provide a comprehensive, immutable record of directory events, including role assignments, role activations, and permission changes. These logs precisely capture the actor, target, timestamp, and metadata for every privilege-modification action, making them the definitive source for tracing how a user acquired elevated rights or escalated privileges.
- ✗
Microsoft Defender for Cloud Apps logs
Why it's wrong here
Microsoft Defender for Cloud Apps (MDA) focuses on behavioral analytics for cloud applications, such as sign-in risk, impossible travel, and file-sharing anomalies. While it can surface suspicious activity that might accompany privilege escalation, it does not log directory-level role assignments or permission modifications; those changes are only recorded in Azure AD audit logs with full fidelity.
- ✗
Microsoft 365 audit logs
Why it's wrong here
Microsoft 365 audit logs aggregate events from workloads like Exchange, SharePoint, and Teams via the unified audit log, and may include some user sign-in events, but they do not capture the complete set of Azure AD directory changes. Role assignments, especially via Privileged Identity Management, produce detailed entries solely in Azure AD audit logs, making that the correct log source for a privilege-escalation inquiry.
Go deeper
Related to this question
About these practice questions
One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.