Courseiva
easyMultiple Choice

SC-200 Practice Question: A SOC analyst needs to create a custom scheduled…

A SOC analyst needs to create a custom scheduled analytics rule in Microsoft Sentinel that detects when a user attempts to sign in from an IP address not in the organization's allowlist. The rule should run every 5 minutes. Which table should the analyst query?

⚠ Common exam trap

Many exam-takers confuse AuditLogs or AzureActivity with sign-in logs, but only SigninLogs contains the interactive user sign-in data with source IP addresses needed for this detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SigninLogs

The SigninLogs table in Microsoft Sentinel captures interactive user sign-in events, including the source IP address. Since the rule needs to detect user sign-in attempts from non-allowlisted IPs, SigninLogs is the correct table to query. It provides the necessary fields like UserPrincipalName, IPAddress, and ResultType to build the detection logic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SigninLogs

    Why this is correct

    In Microsoft Sentinel, the SigninLogs table stores every interactive user sign-in event in Microsoft Entra ID, including the user principal name, IP address utilized, application accessed, and result type (success/failure). Because the source IP is a first-class field in each event, a custom scheduled analytics rule can simply filter SigninLogs by the address in question and alert on any matches. This makes it the definitive data source for detecting sign-in attempts from specific IP addresses, whether they succeeded or were blocked.

  • ✗

    AADNonInteractiveUserSignInLogs

    Why it's wrong here

    AADNonInteractiveUserSignInLogs captures authentication requests made by client applications or services on behalf of a user, not the interactive user sign-in process typical of a human typing credentials into a portal or app. These events often lack a meaningful end-user IP address because traffic may originate from service components, and they are frequently generated in high volume by background processes. Consequently, filtering this table for a suspicious IP would miss the actual attacker sign-in and produce noise from service-level automations.

  • ✗

    AuditLogs

    Why it's wrong here

    AuditLogs in Microsoft Entra ID records tenant administrative actions such as creating a user, updating directory roles, resetting passwords, or changing conditional access policies, but it does not log authentication requests or sign-in sessions. A scheduled analytics rule targeting sign-in attempts from a specific IP would find no corresponding sign-in events in AuditLogs because that table is populated only when a directory change occurs, not when a user logs in. Use AuditLogs to investigate the aftermath of a compromise or to detect policy changes, not to catch authentication attempts.

  • ✗

    AzureActivity

    Why it's wrong here

    AzureActivity is the control-plane log for Azure Resource Manager, containing operations like creating, updating, or deleting Azure resources and the caller information for those management actions. While it includes the caller's IP address, that IP pertains to the person or service performing resource administration, not to a user authenticating to an application or accessing Microsoft 365 resources. Therefore, querying AzureActivity for specific sign-in IP addresses will either return management actions or nothing, making it unsuitable for an identity sign-in detection rule.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.