Courseiva
easyMultiple Choice

SC-200 Practice Question: A security operations analyst is creating a…

A security operations analyst is creating a scheduled analytics rule in Microsoft Sentinel to detect brute force attempts on Microsoft Entra ID authentication. Which data source is most appropriate for this rule?

⚠ Common exam trap

Many exam-takers confuse Azure Activity Logs (control plane) with SigninLogs (authentication plane), assuming all Azure-related logs are in Activity Logs, but Entra ID sign-in events are a separate data source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SigninLogs

SigninLogs captures user authentication attempts to Microsoft Entra ID, including failed sign-ins, which are essential for detecting brute force attacks. This data source provides detailed properties such as IP address, application, and status codes (e.g., 50076 for invalid password), enabling accurate detection of repeated failed attempts. Azure Activity Logs, Office Activity Logs, and SecurityEvent do not contain Entra ID authentication events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Activity Logs

    Why it's wrong here

    Azure Activity Logs capture subscription-level control-plane events such as virtual machine creation, configuration changes, and RBAC modifications. They do not contain sign-in authentication attempts against Microsoft Entra ID because those events are recorded in the identity plane, not the resource management plane. As a result, they cannot provide the repeated failed login data necessary to detect a brute-force attack, making them an incorrect data source for this scheduled rule.

  • ✓

    SigninLogs

    Why this is correct

    SigninLogs in Microsoft Entra ID records both successful and failed user sign-in attempts, including the user principal name, source IP, application, and failure reason. This is the authoritative identity-plane log for detecting brute-force behavior, because you can aggregate sign-in failures per account or IP and compare the count against a threshold, optionally looking for a subsequent success. For a scheduled analytics rule that detects brute-force attacks on cloud identities, SigninLogs is the correct data source.

  • ✗

    Office Activity Logs

    Why it's wrong here

    Office Activity Logs, also called the Microsoft 365 unified audit log, capture workload-level actions inside Exchange Online, SharePoint Online, OneDrive, and Teams, such as mailbox accesses, file downloads, and message sends. These logs do not record the actual authentication attempts that occur at the Microsoft Entra ID security token service, so a failed password attempt is never written here. Therefore, using Office Activity Logs would miss the very sign-in failures that define a brute-force attack and is not a valid choice.

  • ✗

    SecurityEvent

    Why it's wrong here

    The SecurityEvent table in Microsoft Sentinel is populated by Windows security auditing data from on-premises or Azure virtual machines, containing events such as 4624 (successful logon) and 4625 (failed logon) for host sessions. This data is local to individual machines and does not include Microsoft Entra ID sign-ins for cloud applications, which occur at the identity provider boundary. A scheduled rule querying SecurityEvent would therefore detect only host-based brute-force attempts via protocols like RDP, not identity-based attacks against Office 365 or other Entra ID-protected services.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.