mediumMultiple Choice
SC-200 Practice Question: A SOC team uses Microsoft Sentinel and ingests…
A SOC team uses Microsoft Sentinel and ingests Windows Security Events from domain controllers using the Azure Monitor Agent (AMA). They want to create a scheduled analytics rule that generates an incident when a user account is created in a sensitive Active Directory group (e.g., Domain Admins) outside of approved change windows (e.g., after 9 PM). The required event IDs are 4728 (member added to security-enabled global group) and 4732 (member added to security-enabled local group). Which KQL query should the analyst use to filter for these specific events and the targeted group?
⚠ Common exam trap
It's easy for candidates to confuse EventID 4738 (user account changed) or 4624 (logon) with group membership events, or they incorrectly assume the TargetAccount field contains the user account being added rather than the group name.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SecurityEvent | where EventID in (4728, 4732) | where TargetAccount contains 'Domain Admins'
It uses the `SecurityEvent` table with the `EventID` filter for 4728 and 4732, which are the exact event IDs for member additions to security-enabled global and local groups. The `TargetAccount` field contains the name of the group being modified, so filtering for 'Domain Admins' correctly identifies when a user is added to that sensitive group. This query directly matches the requirement to detect account creation in a sensitive AD group outside approved change windows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SecurityEvent | where EventID in (4728, 4732) | where TargetAccount contains 'Domain Admins'
Why this is correct
Security events 4728 and 4732 are generated specifically when a member is added to a security-enabled global group and a security-enabled local group, respectively. By filtering on TargetAccount containing 'Domain Admins', this query captures modifications to the Domain Admins group, which is a common privilege-escalation target. This is the correct approach because it directly monitors group membership changes rather than logon or object-permission events.
- ✗
SecurityEvent | where EventID == 4624 | where Account contains 'Admin'
Why it's wrong here
EventID 4624 indicates a successful logon, not a change to group membership. The filter on Account containing 'Admin' is also misplaced because it looks at the account name associated with the logon session, not the group that was modified. As a result, this query would neither detect a user being added to Domain Admins nor provide useful context about group modifications; it would simply generate logon-related activity, often with a high volume.
- ✗
SecurityEvent | where EventID == 4738 | where TargetAccount contains 'Domain Admins'
Why it's wrong here
EventID 4738 corresponds to changes made to an existing user account, such as password resets, account enablement, or changes to user account control flags. Although the TargetAccount filter might match a username that happens to contain 'Domain Admins,' the event does not record additions to security groups. Using this Event ID would therefore overlook group membership changes and instead report unrelated user administrative operations, creating noise and missing the intended security signal.
- ✗
SecurityEvent | where EventID == 4670 | where ObjectName contains 'Domain Admins'
Why it's wrong here
EventID 4670 is raised when the permissions on a file system or registry object are altered, reflecting DACL modifications rather than Active Directory group membership. Filtering ObjectName for 'Domain Admins' might only catch permission changes on a resource whose name contains that string, such as a folder, not the addition of a principal to the group. This query is designed for object-level access control monitoring, not for detecting group membership additions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.