Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

A security analyst is performing threat hunting in Microsoft Sentinel and wants to identify anomalous outbound network traffic from a compromised virtual machine. Which data source should be prioritized for this hunt?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Network Watcher flow logs

Azure Network Watcher flow logs provide detailed information about IP traffic through Azure networks, making them ideal for detecting anomalous outbound traffic patterns. Option A (Azure Activity Log) focuses on control plane events, not network flows. Option C (Windows Event Logs) is for host-level events, not network traffic. Option D (Microsoft Entra ID sign-in logs) is for authentication events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Activity Log

    Why it's wrong here

    Azure Activity Log is a platform log in Azure that records control-plane events, such as resource creation, deletion, and configuration changes (e.g., 'write' operations via Azure Resource Manager). It does not capture data-plane network traffic, so it cannot reveal actual IP sessions, ports, or the volume of outbound connections from a workload. While it could show when a Network Security Group rule was changed or a public IP was associated, it would not show the malicious outbound connection itself, making it unsuitable for threat hunting network anomalies.

  • ✓

    Azure Network Watcher flow logs

    Why this is correct

    Azure Network Watcher flow logs are the correct source for this hunt because they record IP traffic through network security groups, capturing source/destination IPs, ports, protocols, and whether traffic was allowed or denied. These logs enable security analysts to identify anomalous outbound connections, such as a VM communicating with a known command-and-control (C2) IP on a non-standard port, by analyzing traffic patterns and byte/package counts. However, note that flow logs are aggregate and do not capture packet payloads, so they are best merged with other signals (e.g., threat intelligence) to confirm malicious intent.

  • ✗

    Windows Event Logs (Security, System)

    Why it's wrong here

    Windows Event Logs (Security and System) provide host-level security and operational events, such as logon attempts, privilege use, process creation, and service start/stop, but they do not record raw network flow data like IP addresses, ports, or connection bytes. While Security events (e.g., Event ID 4625) can indicate brute-force attempts and System logs can show driver/network interface issues, they lack the bidirectional flow-level detail needed to trace an outbound connection to an external IP over time. These logs are complementary for endpoint forensics but not a substitute for flow logs when hunting network traffic anomalies.

  • ✗

    Microsoft Entra ID sign-in logs

    Why it's wrong here

    Microsoft Entra ID sign-in logs capture authentication events, including user sign-ins, MFA failures, and conditional access policy results, and are focused on identity and access, not network traffic. They tell you which user logged in and from which IP address, but they do not provide information about other outbound connections from a VM or service, such as a process making an HTTP call to a suspicious domain. Therefore, while useful for detecting compromised identities, they cannot answer the question of whether a specific workload is exfiltrating data or beaconing to C2 infrastructure.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.