SC-200 Perform threat hunting Practice Question
A threat hunter wants to use Microsoft Sentinel to hunt for signs of brute-force attacks against Microsoft Entra ID (now Microsoft Entra ID). Which data connector should be enabled to ingest sign-in logs?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID
Microsoft Entra ID (formerly Azure AD) connector. This connector ingests sign-in logs, which contain authentication attempts and can be used to detect brute-force attacks. Option A (Windows Security Events via AMA) captures on-premises Windows security events, not cloud sign-ins. Option B (DNS Preview) ingests DNS query logs, not sign-in logs. Option C (Microsoft Entra ID Audit Logs) captures audit logs (e.g., user management, configuration changes), not authentication sign-in logs. Therefore, only Option D provides the necessary sign-in log data for hunting brute-force attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Windows Security Events via AMA
Why it's wrong here
Windows Security Events via AMA is incorrect for this hunt because it uses the Azure Monitor Agent to collect Windows Event Logs from on-premises servers or Azure VMs, including local logon and logoff events such as Event ID 4625. These events track operating system-level authentication attempts on the host, not cloud-based sign-ins to Microsoft Entra ID or Microsoft 365 services. Consequently, this connector would not provide the cloud sign-in data needed to analyze identity-based threats.
- ✗
DNS (Preview)
Why it's wrong here
The DNS (Preview) connector is wrong here because it ingests DNS query and response logs from Windows DNS servers, which are valuable for investigating domain name resolution patterns, such as suspicious command-and-control callbacks or DNS tunneling. It contains no sign-in or authentication metadata, so it cannot provide visibility into user logon attempts, failed authentications, or Conditional Access outcomes. DNS logs serve network-layer hunting but are irrelevant for identity-layer sign-in hunting.
- ✗
Microsoft Entra ID Audit Logs
Why it's wrong here
Microsoft Entra ID Audit Logs alone are insufficient because audit logs record security and directory changes such as user creation, group membership updates, and MFA registration modifications, but they do not capture authentication events. While the full Microsoft Entra ID connector includes both sign-in logs and audit logs, selecting only the audit log category would exclude the sign-in records needed to analyze access patterns and detect anomalies. Therefore, this option misses the successful and failed sign-in attempts that are essential for this hunt.
- ✓
Microsoft Entra ID
Why this is correct
Microsoft Entra ID is correct because this data connector streams both sign-in logs and audit logs into Microsoft Sentinel via diagnostic settings. The sign-in logs include interactive, non-interactive, service principal, and managed identity sign-ins, with rich details like MFA result, Conditional Access policy, and risk level. This comprehensive authentication telemetry is exactly what a threat hunter needs to detect unusual or malicious cloud sign-in behavior.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.