Which TWO built-in Microsoft Sentinel hunting queries are useful for detecting signs of compromised credentials?
Anomalous logon location is one of the built-in hunting queries in Microsoft Sentinel, found in the Hunting blade. It uses KQL to analyze sign-in logs, detecting attempts from unexpected geographies or IP addresses, which may indicate compromised credentials or impossible travel. This query is part of Sentinel's predefined hunting pack and is a strong indicator of credential misuse.
Why this answer
Option B, 'Anomalous logon location,' is correct because it flags authentication events where a user signs in from an unusual or unexpected geographic location, which is a classic indicator that credentials have been stolen and are being used by an attacker from a different region. Option C, 'Brute force attempt against user accounts,' is correct because it detects repeated failed authentication attempts followed by a success, directly surfacing password-guessing activity that results in compromised credentials. Option A, 'Baseline of user behavior,' is a general behavioral analytics query that establishes normal activity patterns rather than specifically detecting credential compromise.
Option D, 'Deleted user account,' relates to account lifecycle or destructive actions, not credential theft. Option E, 'New user account creation,' indicates persistence or privilege escalation via a newly created account, not the compromise of existing credentials.
Exam trap
SC-200 often tests whether candidates confuse persistence-related queries (new/deleted accounts) with credential compromise indicators (anomalous logon, brute force), so knowing the exact built-in query names and their purpose is essential.