SC-200 Perform threat hunting Practice Question
A security analyst is performing threat hunting in Microsoft Sentinel and wants to identify anomalous outbound network traffic from a compromised virtual machine. Which data source should be prioritized for this hunt?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Network Watcher flow logs
Azure Network Watcher flow logs provide detailed information about IP traffic through Azure networks, making them ideal for detecting anomalous outbound traffic patterns. Option A (Azure Activity Log) focuses on control plane events, not network flows. Option C (Windows Event Logs) is for host-level events, not network traffic. Option D (Microsoft Entra ID sign-in logs) is for authentication events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Activity Log
Why it's wrong here
Azure Activity Log is a platform log in Azure that records control-plane events, such as resource creation, deletion, and configuration changes (e.g., 'write' operations via Azure Resource Manager). It does not capture data-plane network traffic, so it cannot reveal actual IP sessions, ports, or the volume of outbound connections from a workload. While it could show when a Network Security Group rule was changed or a public IP was associated, it would not show the malicious outbound connection itself, making it unsuitable for threat hunting network anomalies.
- ✓
Azure Network Watcher flow logs
Why this is correct
Azure Network Watcher flow logs are the correct source for this hunt because they record IP traffic through network security groups, capturing source/destination IPs, ports, protocols, and whether traffic was allowed or denied. These logs enable security analysts to identify anomalous outbound connections, such as a VM communicating with a known command-and-control (C2) IP on a non-standard port, by analyzing traffic patterns and byte/package counts. However, note that flow logs are aggregate and do not capture packet payloads, so they are best merged with other signals (e.g., threat intelligence) to confirm malicious intent.
- ✗
Windows Event Logs (Security, System)
Why it's wrong here
Windows Event Logs (Security and System) provide host-level security and operational events, such as logon attempts, privilege use, process creation, and service start/stop, but they do not record raw network flow data like IP addresses, ports, or connection bytes. While Security events (e.g., Event ID 4625) can indicate brute-force attempts and System logs can show driver/network interface issues, they lack the bidirectional flow-level detail needed to trace an outbound connection to an external IP over time. These logs are complementary for endpoint forensics but not a substitute for flow logs when hunting network traffic anomalies.
- ✗
Microsoft Entra ID sign-in logs
Why it's wrong here
Microsoft Entra ID sign-in logs capture authentication events, including user sign-ins, MFA failures, and conditional access policy results, and are focused on identity and access, not network traffic. They tell you which user logged in and from which IP address, but they do not provide information about other outbound connections from a VM or service, such as a process making an HTTP call to a suspicious domain. Therefore, while useful for detecting compromised identities, they cannot answer the question of whether a specific workload is exfiltrating data or beaconing to C2 infrastructure.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.