Courseiva
Perform threat hunting →hardMultiple Choice

SC-200 Perform threat hunting Practice Question

A threat hunter is using Microsoft Sentinel and wants to leverage machine learning to detect anomalous behavior in Azure subscription activity. Which analytics rule template should the hunter use?

⚠ Common exam trap

The trap is confusing sign-in anomaly detection (identity layer) with Azure operations anomaly detection (control-plane layer) — both are ML rules but target different telemetry.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Anomalous Azure Operations

The 'Anomalous Azure Operations' analytics rule template in Microsoft Sentinel uses machine learning to baseline Azure subscription activity and flag unusual operations, which directly matches the hunter's goal of detecting anomalous Azure activity. It is purpose-built for Azure control-plane events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Anomalous Sign-In Locations

    Why it's wrong here

    The Anomalous Sign-In Locations rule in Microsoft Sentinel detects sign-ins originating from unusual geographic regions relative to a user's historical patterns, using data from SigninLogs. This rule does not examine Azure Resource Manager operations, so it cannot identify anomalies in Azure subscription activity such as reshuffled role assignments or unusual resource deletions. While it is a valid identity-based anomaly detection, it is not the correct rule for monitoring Azure operational changes.

  • ✓

    Anomalous Azure Operations

    Why this is correct

    The Anomalous Azure Operations rule is a built-in Microsoft Sentinel analytics rule that uses machine learning to analyze AzureActivity logs and flag unusual operations within an Azure subscription, such as atypical role assignments, resource deployments, or modification of critical settings. Unlike other anomaly rules, it specifically targets the Azure control plane and is driven by the AzureActivity data connector. This rule is the correct choice for a threat hunter seeking to uncover abnormal Azure subscription operations.

  • ✗

    Anomalous User Behavior

    Why it's wrong here

    Anomalous User Behavior in Microsoft Sentinel refers to UEBA (User and Entity Behavior Analytics), which profiles users and entities based on a broad set of activities including sign-ins, resource access, and peer group comparisons. It does not focus specifically on Azure subscription operations like the Anomalous Azure Operations rule, but rather on the user's overall behavior across multiple workloads. This makes it too broad and not tailored to detecting anomalies within Azure Resource Manager activity.

  • ✗

    Lateral Movement Detection

    Why it's wrong here

    Lateral Movement Detection in Microsoft Sentinel is designed to identify techniques used by attackers to move across hosts and networks, such as pass-the-hash, remote service creation, or SMB-based connections, often leveraging Log Analytics agent data and Sysmon logs. It is not concerned with Azure subscription-level operations or AzureActivity log entries. Therefore, it would not alert on anomalies in Azure control plane activities like an unexpected Azure operation, making it an incorrect choice.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.