Courseiva
mediumMultiple Choice

SC-200 Practice Question: A security analyst in Microsoft 365 Defender uses…

A security analyst in Microsoft 365 Defender uses advanced hunting to detect possible credential theft. They want to find instances where a user signed in from an IP address that is not in their organization's known IP range. Which table should they query to get sign-in location and IP address?

⚠ Common exam trap

Many exam-takers confuse DeviceLogonEvents (local device logs) with IdentityLogonEvents (cloud identity logs), failing to recognize that credential theft via cloud sign-ins requires cloud authentication data, not local OS event logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IdentityLogonEvents

IdentityLogonEvents is the correct table because it contains cloud identity logon data from Microsoft Entra ID (formerly Azure AD), including sign-in location, IP address, and user details. This table is specifically designed for hunting authentication-related events like credential theft, where you need to correlate user sign-ins with IP addresses to detect anomalies against known IP ranges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceLogonEvents

    Why it's wrong here

    DeviceLogonEvents records authentication and sign-in activities that occur directly on a device, such as local console, Remote Desktop (RDP), and Kerberos or NTLM logons to the endpoint. Its schema exposes the device name, target account, and process, but it does not capture the client source IP address for cloud service sign-ins. For a Microsoft 365 Defender investigation of a user logging in from a suspicious external IP to a cloud app, this table would miss the relevant Microsoft Entra ID sign-in event.

  • ✓

    IdentityLogonEvents

    Why this is correct

    IdentityLogonEvents is the advanced hunting table that stores authentication events for identities across Microsoft Entra ID and on-premises Active Directory, including both cloud-based and hybrid sign-ins. It includes the user principal name, the source IP address, the application or service targeted, and the authentication result, which makes it the correct table for reviewing a suspicious cloud sign-in IP. Analysts can filter by Timestamp, AccountUpn, and IPAddress to isolate the specific login attempt.

  • ✗

    EmailEvents

    Why it's wrong here

    EmailEvents is an email browsing and processing table: it contains metadata about messages, including sender and recipient addresses, subject, delivery status, and email action such as quarantine or block. It is populated by Microsoft Defender for Office 365 and is useful for mail threat investigations, but it has no record of identity authentication attempts or the network IP address a user signs in from. Therefore, it cannot be used to examine user sign-in events.

  • ✗

    AlertInfo

    Why it's wrong here

    AlertInfo is a keyed reference table rather than a log that stores raw sign-in telemetry. It contains the alert ID, title, severity, category, and detection source for alerts generated by Microsoft 365 Defender, and it is normally joined to AlertEvidence to get actual entities. Since it only provides metadata about alerts—not authentication timestamps, IP addresses, or user logon records—it is not appropriate for querying sign-in events directly.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security analyst is investigating a compromised user account using Microsoft 365 Defender. The analyst wants to see all the sign-in attempts made by this user in the last 24 hours, including the IP addresses and locations. Which advanced hunting table should the analyst query?

easy
  • ✓ A.IdentityLogonEvents
  • B.AlertInfo
  • C.EmailAttachmentInfo
  • D.DeviceLogonEvents

Why A: The IdentityLogonEvents table in Microsoft 365 Defender advanced hunting captures authentication events from Azure Active Directory, including sign-in attempts, IP addresses, and geographic locations. This makes it the correct table for an analyst investigating a compromised user account to review all sign-in activity over the last 24 hours.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.