Courseiva
easyMultiple Choice

SC-200 Practice Question: A security analyst in Microsoft Sentinel wants to…

A security analyst in Microsoft Sentinel wants to create a scheduled analytics rule to detect repeated failed HTTP requests to an Azure Application Gateway, indicating a possible brute force attack. Which Azure Monitor table should the analyst query to capture the access and error logs from the Application Gateway?

⚠ Common exam trap

Test-takers frequently confuse AzureActivity (control plane) with diagnostic logs (data plane), or assume AzureMetrics contains detailed HTTP error data when it only stores aggregated performance counters.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AzureDiagnostics

AzureDiagnostics is the correct table because it stores resource-level logs for Azure services, including Application Gateway access and error logs. These logs contain detailed HTTP request data (e.g., client IP, URI, status code) necessary to detect repeated failed requests indicative of a brute force attack. Other tables like AzureActivity, AzureMetrics, or SecurityEvent do not capture this specific HTTP-level telemetry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AzureActivity

    Why it's wrong here

    AzureActivity is the control-plane audit log for Azure Resource Manager operations, such as the creation, deletion, or configuration change of an Application Gateway and its rules. It captures who performed an operation and when, but it does not capture data-plane traffic like incoming HTTP requests or response codes, which are emitted by the Application Gateway itself to diagnostic logs. Therefore, querying AzureActivity would only show management activity, not the access patterns needed for the analysis.

  • ✓

    AzureDiagnostics

    Why this is correct

    AzureDiagnostics is the correct table because it stores platform-style logs and metrics from Azure resources when diagnostic settings stream them to a Log Analytics workspace, and Sentinel reads from that data plane. For Application Gateway, the diagnostic categories include ApplicationGatewayAccessLog, ApplicationGatewayPerformanceLog, and ApplicationGatewayFirewallLog, all of which land in AzureDiagnostics with fields like clientIP, requestUri, and httpStatus. This makes it the only table here that contains the granular layer-7 HTTP request data required for the investigation, and it can be queried with a filter such as OperationName or ResourceType.

  • ✗

    AzureMetrics

    Why it's wrong here

    AzureMetrics holds only numeric time-series data that Azure Monitor aggregates for resources, such as CPU usage, throughput, and request counts at set intervals. These values summarize activity but do not retain the individual HTTP request characteristics, including client IP addresses, requested URI paths, or user-agent strings, that appear in log-based records. For an Application Gateway, metrics would give you a trend line of requests but no way to drill into specific sessions or payloads, so it is unsuitable for this analysis.

  • ✗

    SecurityEvent

    Why it's wrong here

    SecurityEvent is populated by Windows security audit events collected from virtual machines and servers through the Log Analytics agent, such as logon attempts (Event 4624/4625) and process activity. An Application Gateway is a fully managed Azure PaaS component with no guest operating system from which Sentinel could collect such event logs, and its HTTP access data is always exported via diagnostic settings, not via Windows event forwarding. Using SecurityEvent would therefore be irrelevant, as it contains no network-level request logs for the gateway.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.