Courseiva
mediumMultiple Choice

SC-200 Practice Question: A SOC analyst is creating a scheduled analytics…

A SOC analyst is creating a scheduled analytics rule in Microsoft Sentinel to detect when a user is added to the Global Administrator role in Microsoft Entra ID. The analyst also needs to capture the user who performed the addition. Which Microsoft Entra ID table should the analyst query in the rule's KQL query?

⚠ Common exam trap

Candidates often confuse SigninLogs (which tracks who logged in) with AuditLogs (which tracks who made a change), assuming the actor's identity is always found in sign-in records rather than in directory audit trails.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AuditLogs

The AuditLogs table in Microsoft Entra ID (formerly Azure AD) records all directory-level changes, including role assignments like adding a user to the Global Administrator role. Each audit log entry contains the 'InitiatedBy' property, which captures the user or service principal who performed the action, meeting the analyst's requirement to identify the actor. SigninLogs only tracks authentication events, not administrative changes, making AuditLogs the correct choice for this detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SigninLogs

    Why it's wrong here

    SigninLogs captures authentication events only—each row represents a user signing in, including details like IP address, client app, and conditional access results. It does not record directory administrative actions such as adding a user to a privileged Microsoft Entra ID role, and role change events are never present in this table. Since the detection is for a role assignment, SigninLogs would miss the actor and target entirely, producing no alerts.

  • ✓

    AuditLogs

    Why this is correct

    AuditLogs is the correct table because it contains every write operation on Microsoft Entra ID directory objects, including role management activities like 'Add member to role' or 'Update role'. Each log entry includes the actor (who performed the action), the target (the user or group who received the role), and the exact timestamp, which are essential for a scheduling rule that detects role changes. In Microsoft Sentinel, the AuditLogs table directly maps to the Microsoft Entra ID Audit Log, making it the authoritative source for this detection.

  • ✗

    IdentityInfo

    Why it's wrong here

    IdentityInfo is a curated reference table that stores current user profile data, such as display name, job title, department, and group memberships, but it does not record transactional events. Role assignments are changes in directory membership that occur over time; IdentityInfo would only reflect the eventual state, not the act of assignment, actor, or when it happened. Because the analytics rule needs to detect the actual role change event, querying IdentityInfo would not provide the necessary audit trail.

  • ✗

    BehaviorAnalytics

    Why it's wrong here

    BehaviorAnalytics contains processed output from Microsoft Sentinel's UEBA engine, including anomaly scores, behavioral baselines, and peer comparisons for users. It is derived from historical activity and machine learning models, not raw audit records, and it does not include the granular actor/target details of a specific role assignment. While BehaviorAnalytics can highlight unusual behavior after a role change, it cannot by itself detect the precise directory modification required by the rule.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.