Courseiva
mediumMultiple Choice

SC-200 Practice Question: A SOC analyst is creating a scheduled analytics…

A SOC analyst is creating a scheduled analytics rule in Microsoft Sentinel to detect when a user account is added to a privileged role in Microsoft Entra ID. The analyst wants to correlate with the user's previous role assignments to identify potential privilege escalation. Which table should the analyst query?

⚠ Common exam trap

A common mix-up: candidates confuse AzureActivity (which logs Azure resource operations) with Microsoft Entra ID audit logs, or assume SigninLogs contains role assignment data because it includes directory roles in sign-in token claims.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AuditLogs

The AuditLogs table in Microsoft Sentinel captures directory activity, including changes to privileged role assignments in Microsoft Entra ID (formerly Azure AD). By querying AuditLogs, the analyst can correlate the current role addition with historical role assignment events to detect potential privilege escalation. SigninLogs, AzureActivity, and SecurityEvent do not contain the specific role assignment audit data needed for this correlation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AuditLogs

    Why this is correct

    AuditLogs is the correct table because it captures Microsoft Entra ID directory audit events, including the 'Add member to role' action. This table records the actor, target, and timestamp for every privilege escalation, making it indispensable for detecting suspicious role assignments. Without it, an analytics rule cannot see the actual administrative action that grants elevated permissions.

  • ✗

    SigninLogs

    Why it's wrong here

    SigninLogs is incorrect because it only tracks user authentication attempts, such as successful or failed sign-ins, along with details like IP address and device. It does not record directory role changes or administrative actions. While a user might sign in and then escalate privileges, the role assignment itself is not present in this table, so the rule would miss the critical event.

  • ✗

    AzureActivity

    Why it's wrong here

    AzureActivity is wrong because it contains the operational logs of Azure Resource Manager, such as creating a virtual machine or restarting a resource. Microsoft Entra ID role assignments are not Azure resource operations; they are directory-level changes processed by the Microsoft Graph API. Therefore, this table would not include the 'Add member to role' event that the rule needs.

  • ✗

    SecurityEvent

    Why it's wrong here

    SecurityEvent is not the right choice because it ingests Windows security audit logs from on-premises systems or Azure virtual machines, covering events like logon attempts and process creation. It has no connection to Microsoft Entra ID and cannot see cloud directory changes. An analytics rule querying this table would only monitor endpoint-level activity, not identity privilege escalations.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.