SC-200 Respond to security incidents Practice Question
A security analyst receives a high-severity alert for a suspicious login from an unusual location. The alert was generated by Microsoft Sentinel from Microsoft Entra ID sign-in logs. The analyst needs to determine if the login was successful and if any data exfiltration occurred. What is the MOST efficient first step?
⚠ Common exam trap
The trap here is that candidates often jump to investigating data exfiltration (e.g., checking firewall logs or Defender for Cloud Apps) without first confirming the login was successful, which wastes time and resources if the login actually failed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a KQL query in Microsoft Sentinel to review the SigninLogs table for the user within the alert time range.
The most efficient first step is to run a KQL query in Microsoft Sentinel against the SigninLogs table for the specific user within the alert time range. This directly confirms whether the suspicious login was successful by checking the 'ResultType' and 'ResultDescription' fields, which is the fastest way to validate the alert's core claim before investigating data exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run a KQL query in Microsoft Sentinel to review the SigninLogs table for the user within the alert time range.
Why this is correct
The SigninLogs table in Microsoft Sentinel stores authentication events from Microsoft Entra ID, including interactive and non-interactive sign-ins. Querying this table within the alert time range for the affected user reveals the login success/failure status, source IP, location, MFA result, and conditional access policies applied. This is the authoritative source for validating whether the suspicious sign-in succeeded and assessing the blast radius.
- ✗
Use Microsoft Defender XDR to check the user's device timeline for suspicious activity.
Why it's wrong here
The Microsoft Defender XDR device timeline is an endpoint-centric view that records process, file, and network activity on a specific device, not authentication events that originate from an external IP. A suspicious sign-in may involve the user's credentials but occur before any device becomes involved, so the timeline could be empty or irrelevant. Additionally, device timeline lacks identity-level details like authentication result, MFA state, or conditional access evaluation, making it unsuitable for confirming a sign-in anomaly.
- ✗
Run a KQL query in Microsoft Sentinel to check Microsoft Defender for Cloud Apps alerts for the user.
Why it's wrong here
Microsoft Defender for Cloud Apps alerts are generated from behavioral heuristics and app-visibility policies, meaning they only exist if a custom or built-in policy triggered for the user. They do not contain raw sign-in success/failure records or the full set of authentication properties such as the exact timestamp, IP address, and MFA status. Checking these alerts might surface correlated activity but cannot be relied on to establish whether the specific suspicious sign-in was successful.
- ✗
Check the firewall logs in Azure Firewall for outbound connections from the user's IP.
Why it's wrong here
Azure Firewall logs record network-level allow or deny decisions for flows passing through the firewall, such as source and destination IPs and ports, but they contain no application-layer identity information. A sign-in event is an authentication against Microsoft Entra ID over TLS, so the firewall sees only encrypted connection metadata and cannot determine whether the sign-in succeeded or failed. Therefore, firewall logs are useless for validating a credential-based alert.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.