SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Sentinel with the Microsoft 365 Defender connector. You need to create an analytics rule that generates an incident when a user is reported as compromised by Microsoft Defender for Identity. The rule should use the most efficient method to get this data. What should you use as the data source?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SecurityAlert table with a filter for Defender for Identity.
The SecurityAlert table contains security alerts from various sources, including Microsoft Defender for Identity, when ingested via the Microsoft 365 Defender connector. By filtering for Defender for Identity alerts, you can create an analytics rule that triggers an incident when a user is reported as compromised. This is the most efficient method because the alerts are already available in this table. Option B (DeviceEvents) is from Advanced Hunting and is not directly available in Sentinel tables; it requires running queries against the Microsoft 365 Defender advanced hunting schema, which is less efficient for creating analytics rules. Option C (OfficeActivity) contains Office 365 audit logs, not security alerts. Option D (IdentityInfo) contains identity information such as user details, but not alerts or compromise status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The SecurityAlert table with a filter for Defender for Identity.
Why this is correct
Defender for Identity alerts are normalized into the SecurityAlert table when Sentinel's data connectors ingest them from Microsoft 365 Defender or Azure ATP. This table uses a unified schema for all security alerts, so filtering by the provider or product name (such as 'Azure Advanced Threat Protection') isolates only Defender for Identity detections. Querying SecurityAlert is the correct approach because it is the standard Sentinel table for pre-correlated, high-fidelity security findings, not raw telemetry or audit logs.
- ✗
The DeviceEvents table from Advanced Hunting.
Why it's wrong here
The DeviceEvents table is part of Microsoft 365 Defender's Advanced Hunting schema, not a natively available table in Log Analytics without explicit ingestion. While Sentinel can collect advanced hunting data via the Microsoft 365 Defender connector, you would need to set up something like the Microsoft 365 Defender data connector and then query the raw event-level telemetry from the DeviceEvents table. Even if it were available, DeviceEvents contains process-level events (e.g., file creations, process launches) rather than finished security alerts, so it cannot directly represent Defender for Identity detections like an alert table would.
- ✗
The OfficeActivity table.
Why it's wrong here
The OfficeActivity table stores Microsoft 365 audit logs from Exchange Online, SharePoint, and Teams, capturing user actions such as logins, file access, and mailbox operations. Defender for Identity alerts are not audit log entries; they are security findings generated by detection algorithms that analyze domain controller traffic and other signals. While an alert may correspond to suspicious activity that also appears in audit logs, the alert record itself is never written to OfficeActivity, so this table is unsuitable for querying Defender for Identity detections.
- ✗
The IdentityInfo table.
Why it's wrong here
The IdentityInfo table is a Sentinel watchlist that holds curated identity metadata, such as user names, display names, and department or group memberships, for enrichment purposes rather than alert data. It is typically populated from Microsoft Entra ID or on-premises directories and is used to add context during investigations, not as a source of security detection events. Searching IdentityInfo for Defender for Identity alerts would fail because it contains no timestamped detection records or alert-specific fields like severity, status, or attack technique.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.