SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Exhibit
Refer to the exhibit.
```json
{
"properties": {
"displayName": "Microsoft Sentinel Analytics Rule",
"query": "SecurityEvent
| where EventID == 4625
| summarize Count = count() by Account, bin(TimeGenerated, 5m)
| where Count > 10",
"frequency": "PT5M",
"period": "PT10M",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
}
}
```Refer to the exhibit. You are analyzing a Microsoft Sentinel analytics rule. What does this rule detect?
⚠ Common exam trap
Candidates often confuse a brute-force attack against a single account (detected by failed logons followed by a success for the same user) with a password spray attack (where many accounts are targeted with a few passwords), leading them to incorrectly select an option focused on source IP or overall failure counts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Brute-force attack against a single account
This rule detects a brute-force attack against a single account by triggering when the number of failed logons for a specific user exceeds a threshold within a given time window, followed by a successful logon. The condition `FailedLogons > 5` and `SuccessfulLogon > 0` for the same account indicates that the attacker has guessed the correct password after multiple failed attempts, which is a classic sign of a successful brute-force attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Multiple successful logons for the same account
Why it's wrong here
The analytics rule queries SecurityEvent where EventID == 4625, which is the event ID for failed logon attempts. Successful logons are recorded under EventID 4624 and are not part of the rule's dataset. Since the rule counts only failed logons per account, multiple successful logons would never meet the alert condition and do not indicate a brute-force attack.
- ✓
Brute-force attack against a single account
Why this is correct
This is the correct answer. The KQL rule filters for EventID 4625 (failed logon) and performs a summarize count() by Account over a 5-minute sliding window, alerting when an account's failure count exceeds 10. More than 10 failed logons for the same account within 5 minutes is a strong indicator of an automated brute-force attack, where an attacker tries many password variations against a single user account. The aggregation by Account ensures the alert is specific to one targeted account rather than distributed across users.
- ✗
Multiple failed logons from the same source IP address
Why it's wrong here
The rule does not group or aggregate by the source IP address. Even if many failed logons originate from a single IP, the query only counts failed logons per Account using the Account field, so the rule would not alert unless that same account individually exceeds 10 failures. An attack from one IP across many different accounts would therefore remain undetected because the rule lacks an IP-based grouping dimension.
- ✗
Overall number of failed logons across all accounts
Why it's wrong here
The rule uses a per-account threshold, not a global workspace-wide total. The query groups failed logon events by Account and applies the 'greater than 10' condition to each account group independently. Thus, a total of 100 failed logons spread across 100 different accounts would not trigger the alert, since no single account reaches the threshold—highlighting that the rule detects concentrated attempts on one identity rather than overall failed logon volume.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.