SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your company is deploying Microsoft Defender XDR. You need to design a solution that uses advanced hunting to proactively search for threats. Which THREE data sources should be included in the advanced hunting schema to enable comprehensive threat hunting across endpoints, identities, and cloud apps?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CloudAppEvents
CloudAppEvents (C) is correct because it is the Microsoft Defender for Cloud Apps table in the advanced hunting schema, providing audit and activity events from cloud applications (including Office 365 and other connected apps) needed to hunt for threats in the cloud-app pillar. IdentityInfo (D) is correct because it is the Microsoft Defender for Identity table that supplies identity and account metadata (such as account details, group memberships, and directory context) used to investigate and hunt identity-based attacks. DeviceEvents (E) is correct because it is the Microsoft Defender for Endpoint table containing endpoint event telemetry (such as process, file, registry, and network-related events) that enables hunting across the endpoint pillar. EmailEvents (A) is not among the marked answers because, while it is a valid advanced hunting table for email threats, it is not one of the three sources selected to cover endpoints, identities, and cloud apps in this scenario. AzureActivity (B) is not marked correct because it is an Azure control-plane activity log table rather than a core Defender XDR endpoint, identity, or cloud-app hunting source for this design.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EmailEvents
Why it's wrong here
Although EmailEvents is exposed in the Microsoft 365 Defender advanced hunting schema, its telemetry is entirely scoped to email transport and anti-phishing actions from Defender for Office 365, such as message delivery and URL detonation. It does not contain endpoint process, network connection, or cloud app activity, so it cannot support the cross-domain kill-chain reconstruction described in the scenario. Use it as an email-correlation table, not as the primary hunting surface for multi-domain investigations.
- ✗
AzureActivity
Why it's wrong here
AzureActivity is an Azure Monitor log table that records Azure Resource Manager operations, like virtual machine creation or role assignments, rather than raw security events from endpoint, identity, or cloud apps. Because it lives in a Log Analytics workspace and not in the Microsoft Defender XDR advanced hunting schema, it cannot be joined natively with tables like DeviceEvents or IdentityInfo in the same hunting query. Including it in a Defender XDR advanced hunting search would yield a schema-not-found error or require a separate, less integrated workspace.
- ✓
CloudAppEvents
Why this is correct
CloudAppEvents is the correct table for investigating SaaS application activity because it aggregates sign-in and activity transactions from Defender for Cloud Apps across thousands of cloud apps, including Office 365, AWS, and Google Workspace. Each row contains user, device, IP address, and app-specific action metadata, allowing analysts to pivot from a suspicious identity or endpoint to cloud-side anomalies. This table is one of the five default tables in Defender XDR advanced hunting and is essential for end-to-end, cloud-inclusive threat hunting.
- ✓
IdentityInfo
Why this is correct
IdentityInfo delivers directory metadata from Defender for Identity, including account display name, user principal name, SID, and group memberships, effectively acting as a lookup table for identity-centric hunts. Without it, raw logon and process events remain opaque because they reference only SIDs or PUIDs rather than human-readable account details. It is the bridge that maps a suspicious device event to the actual user or service account, enabling further pivot into CloudAppEvents and EmailEvents.
- ✓
DeviceEvents
Why this is correct
DeviceEvents is a core endpoint telemetry table populated by Microsoft Defender for Endpoint, containing process creation, file creation, network connections, and other low-level sensor actions. This table provides the raw execution and networking evidence needed to trace attacker techniques on a device, and its Timestamp, DeviceId, and AccountSid columns align directly with other XDR tables for join-based correlation. It is arguably the starting point for most advanced hunting queries that begin at an endpoint alert.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.