Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

During a threat hunt in Microsoft Sentinel, you find a series of suspicious sign-ins to Microsoft Entra ID from an IP address known to be associated with a threat actor. Which entity should you pivot on to investigate further?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IP address

The IP address is the key entity that links all suspicious sign-ins and is the initial pivot point for investigation. Option A is correct because the IP address is the common element across the sign-ins. Options B, C, and D are incorrect: the user account, application, and device may be related but are not the primary pivot from the IP address.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    IP address

    Why this is correct

    The IP address is the shared entity linking every suspicious sign-in, letting you pivot to enumerate all related authentication events, affected accounts and associated alerts. Pivoting on the IP exposes the full scope of the threat actor's activity.

  • ✗

    User account

    Why it's wrong here

    Pivoting on the user account traces that identity's activity, but the indicator is a shared source IP, which may span many accounts and reveal the actor's broader targeting. User-centric pivoting suits investigations where a compromised credential, not infrastructure, is the confirmed lead.

  • ✗

    Application

    Why it's wrong here

    Pivoting on the application examines which service the sign-ins targeted, but the threat-actor IP is the pivot point and application data does not enumerate other accounts or hosts touched. Application pivoting suits hunts where a specific enterprise app shows anomalous consent or token activity.

  • ✗

    Device

    Why it's wrong here

    Pivoting on the device assumes the sign-ins originated from managed hardware, yet the known-bad IP is the indicator and may map to no enrolled device. Device pivoting fits investigations where a specific endpoint's compromise, not attacker infrastructure, is established.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.