You are a security analyst at Fabrikam. The company uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. During a threat hunt, you need to identify users who are accessing cloud applications from multiple geographic locations in a short time, which could indicate credential theft or token replay. You want to create a hunting query in Microsoft Sentinel using the CloudAppEvents table. Which approach should you take?
Summarising CloudAppEvents by AccountDisplayName within one-hour bins and filtering where dcount(CountryCode) exceeds one directly surfaces impossible-travel patterns, satisfying the requirement to detect users accessing cloud apps from multiple geographies in a short window. The CloudAppEvents table supplies the CountryCode and TimeGenerated fields this aggregation depends on.
Why this answer
The CloudAppEvents table in Microsoft Sentinel contains Microsoft Defender for Cloud Apps activity logs, including user sign-ins and access to cloud applications with geographic metadata such as CountryCode. Summarizing by AccountDisplayName and binning TimeGenerated into 1-hour windows, then filtering where dcount(CountryCode) > 1, directly detects the impossible-travel pattern described. This is the canonical KQL approach for multi-geo access hunting in Sentinel.
Exam trap
The trap is that candidates pick OfficeActivity or SecurityAlert because they sound like they contain sign-in or location data, but only CloudAppEvents provides the enriched cloud app access telemetry with CountryCode needed for the multi-geo dcount pattern.
How to eliminate wrong answers
Option A is wrong because CommonSecurityLog contains network security appliance logs (e.g., firewalls, proxies) and does not include cloud app user access events with CountryCode — it would not surface the credential-theft pattern. Option B is wrong because OfficeActivity covers Microsoft 365 audit events but does not include the broader cloud app access telemetry (including non-Microsoft SaaS) that CloudAppEvents provides, and it lacks the same CountryCode enrichment. Option C is wrong because SecurityAlert contains generated alerts, not raw access events, so you cannot reliably hunt for the multi-geo pattern from alerts alone.