SC-200 Perform threat hunting Practice Question
A threat hunter is using Microsoft Sentinel and wants to leverage machine learning to detect anomalous behavior in Azure subscription activity. Which analytics rule template should the hunter use?
⚠ Common exam trap
The trap is confusing sign-in anomaly detection (identity layer) with Azure operations anomaly detection (control-plane layer) — both are ML rules but target different telemetry.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anomalous Azure Operations
The 'Anomalous Azure Operations' analytics rule template in Microsoft Sentinel uses machine learning to baseline Azure subscription activity and flag unusual operations, which directly matches the hunter's goal of detecting anomalous Azure activity. It is purpose-built for Azure control-plane events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Anomalous Sign-In Locations
Why it's wrong here
The Anomalous Sign-In Locations rule in Microsoft Sentinel detects sign-ins originating from unusual geographic regions relative to a user's historical patterns, using data from SigninLogs. This rule does not examine Azure Resource Manager operations, so it cannot identify anomalies in Azure subscription activity such as reshuffled role assignments or unusual resource deletions. While it is a valid identity-based anomaly detection, it is not the correct rule for monitoring Azure operational changes.
- ✓
Anomalous Azure Operations
Why this is correct
The Anomalous Azure Operations rule is a built-in Microsoft Sentinel analytics rule that uses machine learning to analyze AzureActivity logs and flag unusual operations within an Azure subscription, such as atypical role assignments, resource deployments, or modification of critical settings. Unlike other anomaly rules, it specifically targets the Azure control plane and is driven by the AzureActivity data connector. This rule is the correct choice for a threat hunter seeking to uncover abnormal Azure subscription operations.
- ✗
Anomalous User Behavior
Why it's wrong here
Anomalous User Behavior in Microsoft Sentinel refers to UEBA (User and Entity Behavior Analytics), which profiles users and entities based on a broad set of activities including sign-ins, resource access, and peer group comparisons. It does not focus specifically on Azure subscription operations like the Anomalous Azure Operations rule, but rather on the user's overall behavior across multiple workloads. This makes it too broad and not tailored to detecting anomalies within Azure Resource Manager activity.
- ✗
Lateral Movement Detection
Why it's wrong here
Lateral Movement Detection in Microsoft Sentinel is designed to identify techniques used by attackers to move across hosts and networks, such as pass-the-hash, remote service creation, or SMB-based connections, often leveraging Log Analytics agent data and Sysmon logs. It is not concerned with Azure subscription-level operations or AzureActivity log entries. Therefore, it would not alert on anomalies in Azure control plane activities like an unexpected Azure operation, making it an incorrect choice.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.