Courseiva

SC-200 Respond to security incidents Practice Question

During an incident investigation, you find that a compromised account was used to log into a virtual machine via RDP from an IP address in a sanctioned country. The VM has Microsoft Defender for Endpoint installed. Which data source in Microsoft Sentinel would you query to see the RDP connection events?

⚠ Common exam trap

Watch out — candidates often confuse cloud sign-in logs (SigninLogs) with local OS logon events, or assume Defender for Endpoint's DeviceLogonEvents is the primary Sentinel table, when in fact SecurityEvent is the correct source for Windows security events collected via the Log Analytics agent.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SecurityEvent

The SecurityEvent table in Microsoft Sentinel collects Windows security events from machines with the Log Analytics agent or Azure Monitor Agent, including Event ID 4625 (failed logon) and Event ID 4624 (successful logon). Since the compromised account used RDP to log into a VM with Defender for Endpoint installed, the RDP connection events are captured as Windows security log events and stored in the SecurityEvent table. This is the correct data source for querying local authentication events on the VM itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceLogonEvents (Microsoft Defender XDR)

    Why it's wrong here

    DeviceLogonEvents is an advanced hunting table belonging to Microsoft Defender XDR (Defender for Endpoint), not a native Sentinel table. While this table can be streamed into Sentinel if the Defender XDR data connector is enabled, it is not the standard location for raw Windows Security events like RDP logons. The canonical source for interactive RDP events (Event ID 4624, LogonType 10) on a Windows VM is the SecurityEvent table, which directly ingests the local Security channel. Therefore, DeviceLogonEvents is an indirect and potentially incomplete source for this investigation.

  • ✗

    CommonSecurityLog

    Why it's wrong here

    CommonSecurityLog is the Sentinel table that normalizes logs in Common Event Format (CEF) from third-party appliances such as Cisco ASA, Palo Alto, or Fortinet; it does not ingest native Windows Event Log data. Windows RDP logons are written to the local Security channel and are collected via the Windows Security Events connectors, not through CEF. Unless you have configured a custom CEF forwarder to selectively send security events—which is not the table's intended use—CommonSecurityLog will not contain the 4624 events needed to trace an RDP compromise. Hence, this option is incorrect for this scenario.

  • ✗

    SigninLogs (Microsoft Entra ID)

    Why it's wrong here

    SigninLogs is part of Microsoft Entra ID (formerly Azure AD) and tracks interactive and non-interactive sign-ins to cloud applications and Azure resources, not the local OS security event log of a Windows VM. RDP authentication against a VM's local accounts or Active Directory occurs during the Windows logon process and is recorded only in the operating system's Security log as Event ID 4624. Entra ID sign-in logs would not include local RDP sessions unless Microsoft Entra ID authentication for RDP is explicitly configured, and even then they lack the full local session details (source IP, session type). Thus, this table is unsuitable for investigating RDP access on the compromised VM.

  • ✓

    SecurityEvent

    Why this is correct

    SecurityEvent is the correct table because it contains Windows Security event logs, including Event ID 4624 (successful logon) and 4625 (failed logon), which are essential for RDP investigations. When an RDP session is established on a Windows VM, the local Security channel generates a 4624 with LogonType 10 (RemoteInteractive), and this data is sent to Sentinel via the Windows Security Events data connector (using either the legacy Log Analytics agent or the Azure Monitor Agent). From this table you can query the source IP, source port, and account that performed the RDP logon to identify indicators of compromise. Thus, SecurityEvent is the authoritative and most direct source for RDP logon activity in Microsoft Sentinel.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.