Courseiva
mediumMultiple Select

SC-200 Practice Question: A SOC analyst is building a scheduled analytics…

A SOC analyst is building a scheduled analytics rule in Microsoft Sentinel to detect when a user is added to a privileged Microsoft Entra ID role (e.g., Global Administrator). Which two tables must be included in the KQL query to capture the role assignment event and to retrieve user details? (Choose 2.)

⚠ Common exam trap

A common mix-up: candidates confuse SigninLogs (which only records authentication attempts) with AADAuditLogs (which records administrative changes), or they overlook IdentityInfo as a separate table needed for user details, assuming the audit log alone provides all necessary user attributes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AADAuditLogs

AADAuditLogs captures all directory audit events, including role assignment activities such as adding a user to a privileged Microsoft Entra ID role. This table is essential because it records the 'Add member to role' operation with details like the target user, role name, and initiating actor, which are required to detect the security event.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AADAuditLogs

    Why this is correct

    AADAuditLogs is the correct choice because it is the Microsoft Entra ID audit log that records every directory write operation, including role assignments. Activities such as "Add member to role," "Remove member from role," and PIM role activations are captured here, making it the authoritative table for detecting changes to privileged role membership. A scheduled analytics rule can query this table directly to alert on unexpected or high-risk role assignment events.

  • ✗

    SigninLogs

    Why it's wrong here

    SigninLogs is not a valid source for role assignment events because it only contains authentication and sign-in activity—both interactive and non-interactive—such as user logons, conditional access evaluations, and sign-in failures. Role assignments are administrative directory changes that occur outside of the sign-in process, so they never appear in this table. While SigninLogs is useful for detecting anomalous sign-ins, it cannot be used to audit role membership modifications.

  • ✗

    AzureActivity

    Why it's wrong here

    AzureActivity logs Azure Resource Manager control-plane operations, such as deploying VMs, modifying network security groups, or changing resource settings, but it does not include Microsoft Entra ID directory changes. Role assignments are tenant-level changes made through Microsoft Graph or the Entra admin center, not Azure resource operations, so they are written to AADAuditLogs instead. Relying on AzureActivity would miss all role assignment activity and is therefore incorrect for this detection.

  • ✓

    IdentityInfo

    Why this is correct

    IdentityInfo is indeed a useful table for contextual enrichment, but it does not store audit events for role assignments. This table contains static identity metadata such as display names, department, job title, and manager, which can be joined to AADAuditLogs to add context to an alert. However, since it lacks historical activity data, it cannot serve as the source for detecting role assignment changes and should be used only for enrichment in a scheduled query.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.