easyMultiple Choice
SC-200 Practice Question: A security analyst in Microsoft Sentinel wants to…
A security analyst in Microsoft Sentinel wants to create a scheduled analytics rule to detect repeated failed HTTP requests to an Azure Application Gateway, indicating a possible brute force attack. Which Azure Monitor table should the analyst query to capture the access and error logs from the Application Gateway?
⚠ Common exam trap
Test-takers frequently confuse AzureActivity (control plane) with diagnostic logs (data plane), or assume AzureMetrics contains detailed HTTP error data when it only stores aggregated performance counters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AzureDiagnostics
AzureDiagnostics is the correct table because it stores resource-level logs for Azure services, including Application Gateway access and error logs. These logs contain detailed HTTP request data (e.g., client IP, URI, status code) necessary to detect repeated failed requests indicative of a brute force attack. Other tables like AzureActivity, AzureMetrics, or SecurityEvent do not capture this specific HTTP-level telemetry.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AzureActivity
Why it's wrong here
AzureActivity is the control-plane audit log for Azure Resource Manager operations, such as the creation, deletion, or configuration change of an Application Gateway and its rules. It captures who performed an operation and when, but it does not capture data-plane traffic like incoming HTTP requests or response codes, which are emitted by the Application Gateway itself to diagnostic logs. Therefore, querying AzureActivity would only show management activity, not the access patterns needed for the analysis.
- ✓
AzureDiagnostics
Why this is correct
AzureDiagnostics is the correct table because it stores platform-style logs and metrics from Azure resources when diagnostic settings stream them to a Log Analytics workspace, and Sentinel reads from that data plane. For Application Gateway, the diagnostic categories include ApplicationGatewayAccessLog, ApplicationGatewayPerformanceLog, and ApplicationGatewayFirewallLog, all of which land in AzureDiagnostics with fields like clientIP, requestUri, and httpStatus. This makes it the only table here that contains the granular layer-7 HTTP request data required for the investigation, and it can be queried with a filter such as OperationName or ResourceType.
- ✗
AzureMetrics
Why it's wrong here
AzureMetrics holds only numeric time-series data that Azure Monitor aggregates for resources, such as CPU usage, throughput, and request counts at set intervals. These values summarize activity but do not retain the individual HTTP request characteristics, including client IP addresses, requested URI paths, or user-agent strings, that appear in log-based records. For an Application Gateway, metrics would give you a trend line of requests but no way to drill into specific sessions or payloads, so it is unsuitable for this analysis.
- ✗
SecurityEvent
Why it's wrong here
SecurityEvent is populated by Windows security audit events collected from virtual machines and servers through the Log Analytics agent, such as logon attempts (Event 4624/4625) and process activity. An Application Gateway is a fully managed Azure PaaS component with no guest operating system from which Sentinel could collect such event logs, and its HTTP access data is always exported via diagnostic settings, not via Windows event forwarding. Using SecurityEvent would therefore be irrelevant, as it contains no network-level request logs for the gateway.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.