SC-200 Respond to security incidents Practice Question
During an investigation, you need to check if any user has been assigned privileged roles in Microsoft Entra ID outside of normal business hours. Which data source would provide this information?
⚠ Common exam trap
Watch out — candidates often confuse SigninLogs (which show when a user logs in) with AuditLogs (which show administrative changes like role assignments), leading them to choose Option C incorrectly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AuditLogs (Microsoft Entra ID)
AuditLogs in Microsoft Entra ID (formerly Azure AD) capture all directory-level changes, including privileged role assignments (e.g., Global Administrator, Privileged Role Administrator) along with the timestamp and user who performed the action. This allows you to filter for role assignments occurring outside normal business hours, making it the correct data source for this investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
OfficeActivity (Office 365)
Why it's wrong here
OfficeActivity (Office 365) tracks user and admin actions across Exchange, SharePoint, Teams, and other Office 365 workloads, such as mailbox access or file downloads. It does not capture Entra ID directory changes, so role assignment events like 'Add member to role' will never appear in this table. While the Unified Audit Log also includes Microsoft Entra ID events, the OfficeActivity schema specifically lacks the RoleManagement category. Therefore, it is not suitable for this investigation.
- ✗
SecurityEvent (Windows Event Logs)
Why it's wrong here
SecurityEvent (Windows Event Logs) ingests on-premises Windows security events from domain controllers and servers, including event IDs like 4728 or 4732 for local/AD group membership changes. These events are generated by Windows, not by Microsoft Entra ID, and they do not reflect cloud role assignments in Microsoft Entra ID. A privileged role added to a user in Entra ID does not create a SecurityEvent on any host. Thus, this table cannot be used to detect such a change.
- ✗
SigninLogs (Microsoft Entra ID)
Why it's wrong here
SigninLogs (Microsoft Entra ID) records authentication attempts, including user sign-ins, application logons, conditional access outcomes, and risk signals. These logs answer 'who logged in and when,' but they contain no information about who was assigned a directory role. Role assignment is a configuration change to an identity object, not an authentication event, so it is outside the scope of SigninLogs. This makes it an invalid data source for detecting role assignments.
- ✓
AuditLogs (Microsoft Entra ID)
Why this is correct
AuditLogs (Microsoft Entra ID) is the authoritative log for directory administrative changes, capturing activities such as 'Add member to role,' 'Remove member from role,' and 'Activate role' in the RoleManagement category. Each log entry includes the actor, target user, role name, and timestamp, enabling full visibility into who was granted elevated permissions and when. In Log Analytics or Microsoft 365 Defender, this appears as the AuditLogs table in the EntraID sign-in/logs connector. Therefore, it is the correct data source for verifying whether any user has been added to a privileged role.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.