Courseiva
mediumMultiple Choice

SC-200 Practice Question: A security team uses Microsoft Defender for Cloud…

A security team uses Microsoft Defender for Cloud with Defender for Servers enabled. They want to receive an alert whenever a new local user is added to the Administrators group on any Azure Windows virtual machine. Which data source must be configured in Defender for Cloud to capture this event?

⚠ Common exam trap

Candidates often confuse Azure Activity Logs (control-plane) with guest OS security events, assuming any Azure-level log will capture local user changes, but only the Windows Security Events data source collects the necessary Event ID 4732 from within the VM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows Security Events (Event ID 4732)

The addition of a user to the Administrators group on a Windows system generates Windows Security Event ID 4732. Defender for Cloud with Defender for Servers must have the 'Windows Security Events' data source configured to collect these audit events, which then triggers a security alert for the new local administrator.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Windows Security Events (Event ID 4732)

    Why this is correct

    Event 4732 is generated by the Windows security audit policy whenever a user or group is added to a security-enabled local group, such as the Administrators group. Defender for Cloud collects Windows Security Events through the Log Analytics agent or Azure Monitor Agent, allowing custom alerts or the built-in 'Security event log' Analytics rule to detect these membership changes. This is the correct data source because it directly captures the OS-level audit trail of local group modification.

  • ✗

    Windows Defender Antivirus logs

    Why it's wrong here

    Windows Defender Antivirus logs, delivered via the 'Windows Defender Antivirus' data source in Defender for Cloud, record malware detection, real-time protection, and threat remediation events (e.g., Event IDs 1116 and 1117) from the endpoint. These logs contain no group-membership or user-account audit entries, so they cannot reveal when an account was added to a privileged local group. Additionally, relying on antivirus logs would only indicate threats, not administrative actions.

  • ✗

    Azure Activity Logs

    Why it's wrong here

    Azure Activity Logs are a subscription-level, control-plane audit trail that record operations on Azure resources, such as VM creation, deletion, or role assignment via ARM. Local group membership changes inside a Windows VM are data-plane and OS-level events that never appear in the Activity Log, because that log lacks visibility into guest operating system activities. Thus, while Activity Logs are essential for cloud governance, they are an invalid source for detecting on-premises-style local group additions.

  • ✗

    VM Insights

    Why it's wrong here

    VM Insights is a monitoring solution for Azure VMs and VM scale sets that gathers performance counters, health states, and dependency/downstream connection mapping through the Map service. It intentionally focuses on operational telemetry and network topology, not security-audit or identity-management events. Therefore, it cannot capture Event ID 4732 or any local group membership changes, making it an entirely wrong source for this detection.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.