Courseiva
easyMultiple Choice

SC-200 Practice Question: A security analyst is using advanced hunting in…

A security analyst is using advanced hunting in Microsoft 365 Defender to investigate a potential brute-force attack against an on-premises Exchange server. The analyst wants to find authentication failures from a specific IP address. Which table should the analyst query?

⚠ Common exam trap

Many candidates confuse DeviceLogonEvents (endpoint-focused) with IdentityLogonEvents (identity-focused), forgetting that on-premises Exchange authentication is handled by Active Directory and monitored by Defender for Identity, not by endpoint sensors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IdentityLogonEvents

IdentityLogonEvents is the correct table because it captures authentication attempts monitored by Microsoft Defender for Identity, which deploys a dedicated sensor directly on Active Directory Domain Controllers (and optionally AD FS/AD CS servers) to inspect Kerberos, NTLM, and LDAP traffic in real time. This gives visibility into on-premises Exchange server authentication against Active Directory, including details such as account, target device, IP address, protocol, and success/failure status. This table is specifically designed for identity sign-in events, making it the right choice in Advanced Hunting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    EmailEvents

    Why it's wrong here

    EmailEvents stores metadata about email messages processed by Exchange Online Protection and Microsoft 365, including delivery status, sender/recipient, and detection results. It does not contain authentication or logon attempts, so it cannot be used to investigate on-premises Exchange server authentication activity. For authentication events, you need a table that records identity logons rather than email flow.

  • ✓

    IdentityLogonEvents

    Why this is correct

    IdentityLogonEvents is the correct table because it captures authentication attempts for both cloud and on-premises identity infrastructure, including servers connected to Microsoft Entra ID via Active Directory Federation Services or Password Hash Sync. It includes details such as user, target application, IP address, and success or failure status for logons against Active Directory, which covers on-premises Exchange authentication. This table is specifically designed for identity sign-in events, making it the right choice in Advanced Hunting.

  • ✗

    DeviceLogonEvents

    Why it's wrong here

    DeviceLogonEvents tracks logon activity to specific Windows devices, such as local console logons, remote desktop, and network logons to the device itself. It does not record application-level authentication to services like Exchange Server, because that occurs against Active Directory rather than as a device logon event. On-premises Exchange authentication would not appear in this table, which focuses on the device security logs.

  • ✗

    CloudAppEvents

    Why it's wrong here

    CloudAppEvents is populated with activities and events from cloud applications, including Office 365, Dynamics 365, and third-party SaaS apps, but not from on-premises Exchange servers. It contains sign-in activities to cloud apps, not authentication to on-premises infrastructure. Since the question asks about on-premises Exchange server authentication, CloudAppEvents is not the appropriate table to query.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.