Which THREE data sources should be included in a Microsoft Sentinel workspace to comprehensively monitor for lateral movement within an Azure environment?
Microsoft Entra ID sign-in logs record authentication events, including the originating IP, device and conditional access outcome. They satisfy the lateral movement requirement by exposing credential reuse or anomalous sign-ins from compromised accounts moving between Azure resources.
Why this answer
Azure AD sign-in logs (A) are correct because they record authentication events, including risky sign-ins, IP addresses, and conditional access results, which are essential for detecting credential-based lateral movement across Azure resources. Azure Network Security Group flow logs (C) are correct because they capture allowed and denied IP traffic flows through NSGs, enabling detection of east-west movement between subnets and VMs. Azure Activity logs (E) are correct because they record control-plane operations such as role assignments, resource creation, and management actions that attackers use to pivot and escalate privileges.
Power BI audit logs (B) and Azure DevOps audit logs (D) are not included because they focus on BI and DevOps activities, not on authentication, network, or Azure control-plane events relevant to lateral movement monitoring.
Exam trap
SC-200 often tests whether candidates can distinguish Azure runtime telemetry (sign-in, NSG flow, Activity logs) from SaaS/productivity audit logs (Power BI, DevOps) that do not reflect Azure infrastructure lateral movement.