Courseiva
easyMultiple Choice

SC-200 Practice Question: A security analyst is investigating a compromised…

A security analyst is investigating a compromised user account using Microsoft 365 Defender. The analyst wants to see all the sign-in attempts made by this user in the last 24 hours, including the IP addresses and locations. Which advanced hunting table should the analyst query?

⚠ Common exam trap

It's easy for candidates to confuse DeviceLogonEvents (which covers local Windows logons) with IdentityLogonEvents (which covers cloud-based Microsoft Entra ID sign-ins), leading them to select the wrong table for investigating cloud account compromises.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IdentityLogonEvents

The IdentityLogonEvents table in Microsoft 365 Defender advanced hunting captures authentication events from Microsoft Entra ID, including sign-in attempts, IP addresses, and geographic locations. This makes it the correct table for an analyst investigating a compromised user account to review all sign-in activity over the last 24 hours.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    IdentityLogonEvents

    Why this is correct

    IdentityLogonEvents is an advanced hunting table in Microsoft 365 Defender that stores raw authentication events for user sign-ins to Microsoft Entra ID (formerly Azure AD). Each record captures the account UPN, IP address, geographic location, application, client type, and success or failure status, enabling analysts to trace a compromised account's activity across cloud resources. To investigate a compromised user, this table is the authoritative source for sign-in attempts, including impossible travel anomalies and repeated failures.

  • ✗

    AlertInfo

    Why it's wrong here

    AlertInfo is a schema table that provides the authoritative metadata for security alerts raised across Microsoft 365 Defender services, such as alert ID, title, severity, category, and MITRE technique. It does not contain the underlying raw event data that describes how a sign-in occurred, such as the source IP or geographic coordinates. While an alert about a threat actor may link to related evidence, the actual sign-in events would have to be retrieved from IdentityLogonEvents, not AlertInfo.

  • ✗

    EmailAttachmentInfo

    Why it's wrong here

    EmailAttachmentInfo belongs to the email-centric hunting tables and contains file attachment metadata, including attachment name, file type, size, sender/recipient context, and SHA-256 hash, for messages processed through Exchange Online. It is pertinent to investigations involving phishing links or malicious payloads, but it has no relationship to user logon activity in Microsoft Entra ID. For a compromised account, you would not query this table to find sign-in IPs or timestamps.

  • ✗

    DeviceLogonEvents

    Why it's wrong here

    DeviceLogonEvents records logon and sign-out activities that occur directly on endpoint devices protected by Microsoft Defender for Endpoint, such as interactive, remote, and service logons. These events include caller and logon process details and are focused on the local Windows security stack, not on cloud authentication to Microsoft Entra ID. Although a compromised user may also produce device logons, the distinct cloud sign-in events against Entra ID live in IdentityLogonEvents, making DeviceLogonEvents insufficient for this investigation.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.