SC-200 Perform threat hunting Practice Question
During a threat hunt in Microsoft Sentinel, you find a series of suspicious sign-ins to Microsoft Entra ID from an IP address known to be associated with a threat actor. Which entity should you pivot on to investigate further?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IP address
The IP address is the key entity that links all suspicious sign-ins and is the initial pivot point for investigation. Option A is correct because the IP address is the common element across the sign-ins. Options B, C, and D are incorrect: the user account, application, and device may be related but are not the primary pivot from the IP address.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IP address
Why this is correct
The IP address is the shared entity linking every suspicious sign-in, letting you pivot to enumerate all related authentication events, affected accounts and associated alerts. Pivoting on the IP exposes the full scope of the threat actor's activity.
- ✗
User account
Why it's wrong here
Pivoting on the user account traces that identity's activity, but the indicator is a shared source IP, which may span many accounts and reveal the actor's broader targeting. User-centric pivoting suits investigations where a compromised credential, not infrastructure, is the confirmed lead.
- ✗
Application
Why it's wrong here
Pivoting on the application examines which service the sign-ins targeted, but the threat-actor IP is the pivot point and application data does not enumerate other accounts or hosts touched. Application pivoting suits hunts where a specific enterprise app shows anomalous consent or token activity.
- ✗
Device
Why it's wrong here
Pivoting on the device assumes the sign-ins originated from managed hardware, yet the known-bad IP is the indicator and may map to no enrolled device. Device pivoting fits investigations where a specific endpoint's compromise, not attacker infrastructure, is established.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.