mediumMultiple Choice
SC-200 Practice Question: A SOC analyst is creating a scheduled analytics…
A SOC analyst is creating a scheduled analytics rule in Microsoft Sentinel to detect when a user account is added to a privileged role in Microsoft Entra ID. The analyst wants to correlate with the user's previous role assignments to identify potential privilege escalation. Which table should the analyst query?
⚠ Common exam trap
A common mix-up: candidates confuse AzureActivity (which logs Azure resource operations) with Microsoft Entra ID audit logs, or assume SigninLogs contains role assignment data because it includes directory roles in sign-in token claims.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AuditLogs
The AuditLogs table in Microsoft Sentinel captures directory activity, including changes to privileged role assignments in Microsoft Entra ID (formerly Azure AD). By querying AuditLogs, the analyst can correlate the current role addition with historical role assignment events to detect potential privilege escalation. SigninLogs, AzureActivity, and SecurityEvent do not contain the specific role assignment audit data needed for this correlation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AuditLogs
Why this is correct
AuditLogs is the correct table because it captures Microsoft Entra ID directory audit events, including the 'Add member to role' action. This table records the actor, target, and timestamp for every privilege escalation, making it indispensable for detecting suspicious role assignments. Without it, an analytics rule cannot see the actual administrative action that grants elevated permissions.
- ✗
SigninLogs
Why it's wrong here
SigninLogs is incorrect because it only tracks user authentication attempts, such as successful or failed sign-ins, along with details like IP address and device. It does not record directory role changes or administrative actions. While a user might sign in and then escalate privileges, the role assignment itself is not present in this table, so the rule would miss the critical event.
- ✗
AzureActivity
Why it's wrong here
AzureActivity is wrong because it contains the operational logs of Azure Resource Manager, such as creating a virtual machine or restarting a resource. Microsoft Entra ID role assignments are not Azure resource operations; they are directory-level changes processed by the Microsoft Graph API. Therefore, this table would not include the 'Add member to role' event that the rule needs.
- ✗
SecurityEvent
Why it's wrong here
SecurityEvent is not the right choice because it ingests Windows security audit logs from on-premises systems or Azure virtual machines, covering events like logon attempts and process creation. It has no connection to Microsoft Entra ID and cannot see cloud directory changes. An analytics rule querying this table would only monitor endpoint-level activity, not identity privilege escalations.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.