Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

A threat hunter is investigating a potential compromise involving a user account that has been used to sign in from multiple locations within a short time. The hunter wants to use Microsoft Sentinel to find all sign-in events for that user from different IP addresses in the last 24 hours. Which KQL query should be used?

⚠ Common exam trap

SC-200 often tests whether candidates know which Sentinel table holds which telemetry type — specifically confusing Microsoft Entra ID sign-in data (SigninLogs) with audit activity (AuditLogs) or on-prem Windows logons (SecurityEvent).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SigninLogs | where TimeGenerated > ago(24h) | where UserPrincipalName == "user@domain.com" | summarize count() by IPAddress

The SigninLogs table in Microsoft Sentinel stores Microsoft Entra ID (Entra ID) interactive and non-interactive sign-in events, including the UserPrincipalName and IPAddress fields needed to trace a user's authentication activity across locations. Querying SigninLogs with a 24-hour time filter, matching on UserPrincipalName, and summarizing by IPAddress directly answers the hunter's question about which IPs the account signed in from. This is the canonical table for identity-based sign-in hunting in Sentinel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SigninLogs | where TimeGenerated > ago(24h) | where UserPrincipalName == "user@domain.com" | summarize count() by IPAddress

    Why this is correct

    SigninLogs holds Microsoft Entra ID interactive sign-in events with UserPrincipalName and IPAddress, so filtering the last 24 hours and summarising by IPAddress satisfies the requirement to enumerate distinct source addresses for that user. AADNonInteractiveUserSignInLogs would not match interactive portal sign-ins.

  • ✗

    SecurityEvent | where TimeGenerated > ago(24h) | where TargetUserName == "user@domain.com" | summarize count() by IpAddress

    Why it's wrong here

    SecurityEvent holds Windows event log data, not Entra ID sign-in logs, so TargetUserName and IpAddress would not reflect interactive sign-ins. It tempts because SecurityEvent is the default table for many Sentinel hunting queries. SigninLogs is the correct table for Microsoft Entra ID sign-in events.

  • ✗

    AuditLogs | where TimeGenerated > ago(24h) | where InitiatedBy.user.userPrincipalName == "user@domain.com" | summarize count() by IPAddress

    Why it's wrong here

    AuditLogs holds directory activity such as role changes, not interactive sign-in records, and its InitiatedBy field describes the actor performing the operation. It is tempting because AuditLogs does capture user identity events, so it would be correct for tracing administrative actions rather than locating sign-in IP addresses.

  • ✗

    CommonSecurityLog | where TimeGenerated > ago(24h) | where SourceUserID == "user@domain.com" | summarize count() by SourceIP

    Why it's wrong here

    CommonSecurityLog ingests third-party CEF data forwarded by connectors, so Microsoft Entra sign-in events are absent unless separately streamed. It is tempting because it does contain SourceIP and user fields, which would be correct for correlating firewall or proxy logs rather than native Entra ID sign-in telemetry.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.