Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "displayName": "Microsoft Sentinel Analytics Rule",
    "query": "SecurityEvent
| where EventID == 4625
| summarize Count = count() by Account, bin(TimeGenerated, 5m)
| where Count > 10",
    "frequency": "PT5M",
    "period": "PT10M",
    "triggerOperator": "GreaterThan",
    "triggerThreshold": 0
  }
}
```

Refer to the exhibit. You are analyzing a Microsoft Sentinel analytics rule. What does this rule detect?

⚠ Common exam trap

Candidates often confuse a brute-force attack against a single account (detected by failed logons followed by a success for the same user) with a password spray attack (where many accounts are targeted with a few passwords), leading them to incorrectly select an option focused on source IP or overall failure counts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Brute-force attack against a single account

This rule detects a brute-force attack against a single account by triggering when the number of failed logons for a specific user exceeds a threshold within a given time window, followed by a successful logon. The condition `FailedLogons > 5` and `SuccessfulLogon > 0` for the same account indicates that the attacker has guessed the correct password after multiple failed attempts, which is a classic sign of a successful brute-force attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Multiple successful logons for the same account

    Why it's wrong here

    The analytics rule queries SecurityEvent where EventID == 4625, which is the event ID for failed logon attempts. Successful logons are recorded under EventID 4624 and are not part of the rule's dataset. Since the rule counts only failed logons per account, multiple successful logons would never meet the alert condition and do not indicate a brute-force attack.

  • ✓

    Brute-force attack against a single account

    Why this is correct

    This is the correct answer. The KQL rule filters for EventID 4625 (failed logon) and performs a summarize count() by Account over a 5-minute sliding window, alerting when an account's failure count exceeds 10. More than 10 failed logons for the same account within 5 minutes is a strong indicator of an automated brute-force attack, where an attacker tries many password variations against a single user account. The aggregation by Account ensures the alert is specific to one targeted account rather than distributed across users.

  • ✗

    Multiple failed logons from the same source IP address

    Why it's wrong here

    The rule does not group or aggregate by the source IP address. Even if many failed logons originate from a single IP, the query only counts failed logons per Account using the Account field, so the rule would not alert unless that same account individually exceeds 10 failures. An attack from one IP across many different accounts would therefore remain undetected because the rule lacks an IP-based grouping dimension.

  • ✗

    Overall number of failed logons across all accounts

    Why it's wrong here

    The rule uses a per-account threshold, not a global workspace-wide total. The query groups failed logon events by Account and applies the 'greater than 10' condition to each account group independently. Thus, a total of 100 failed logons spread across 100 different accounts would not trigger the alert, since no single account reaches the threshold—highlighting that the rule detects concentrated attempts on one identity rather than overall failed logon volume.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.