Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

During a threat hunt, you notice an anomalous number of failed logon attempts from a single IP address across multiple user accounts in Microsoft Entra ID sign-in logs. What is the most effective next step to determine if this is a brute-force attack?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Correlate with successful logon events from the same IP for those accounts

Correlating failed logon attempts with successful logon events from the same IP address for the same accounts is the most effective next step. If a successful logon occurs shortly after failures, it strongly indicates a brute-force attack succeeded. This evidence justifies further action like blocking the IP or resetting the compromised account. Option A (blocking IP immediately) may be premature without confirming success. Option B (resetting all affected passwords) is disruptive and may not address the root cause if no breach occurred. Option C (disabling accounts) could block legitimate users unnecessarily.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately block the IP address in the firewall

    Why it's wrong here

    Blocking the IP is a containment action that stops traffic but gathers no evidence about whether the failures are brute force, password spray, or misconfiguration. It tempts as an immediate protective reflex, yet the hunt question asks for investigation, which requires correlating sign-in log patterns first.

  • ✗

    Reset passwords for all affected accounts

    Why it's wrong here

    Resetting passwords disrupts users without confirming the attack pattern, and the anomalous failed logons would continue from that IP. Password resets suit confirmed credential compromise, not investigation. Correlating the source IP, timing and targeted accounts in the sign-in logs reveals whether the pattern is brute force.

  • ✗

    Disable the accounts that had failed logons

    Why it's wrong here

    Disabling accounts is containment, not investigation, and would lock out legitimate users without confirming attack intent. It tempts because disabling compromised identities is standard incident response, but the stem asks how to determine whether this is brute force, which needs log correlation and analysis before remediation.

  • ✓

    Correlate with successful logon events from the same IP for those accounts

    Why this is correct

    Correlating successful logon events from the same IP against those accounts reveals whether the failed attempts culminated in compromise, distinguishing brute-force success from mere noise. This directly satisfies the stem's goal of determining whether the activity constitutes an actual brute-force attack rather than isolated failures.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.