Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.
```kql
let TimeRange = 7d;
let Threshold = 100;
SigninLogs
| where TimeGenerated > ago(TimeRange)
| where ResultType == "50057"
| summarize Attempts = count() by UserPrincipalName, IPAddress
| where Attempts > Threshold
```

Refer to the exhibit. The KQL query is used in a Microsoft Sentinel scheduled alert rule. What scenario does this query detect?

⚠ Common exam trap

Many candidates confuse the generic 'sign-in failure' concept with the specific `ResultType` code 50057, assuming any failure could indicate brute force or MFA issues, when in fact each code maps to a distinct Microsoft Entra ID error condition.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attempts to sign in with disabled user accounts.

The KQL query filters for `ResultType == 50057`, which specifically indicates a sign-in attempt by a disabled user account in Microsoft Entra ID. This result type is unique to disabled accounts and does not cover MFA denials (53003), invalid password attempts (50126), or brute force patterns. Therefore, the query detects attempts to sign in with disabled user accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Multiple MFA denial events from a single user.

    Why it's wrong here

    MFA denial events are represented by distinct Microsoft Entra ID error codes such as 500121 (authentication method required) or 500133 (claim in token is missing or invalid), not by 50057. These denials occur only after the user successfully authenticates their password, whereas a disabled account is rejected before any MFA challenge is issued. Because the query filters specifically on ResultType 50057, it would not capture MFA denial events.

  • ✗

    Brute force attacks against Microsoft Entra ID accounts using invalid passwords.

    Why it's wrong here

    Invalid password attempts trigger ResultType 50126, which indicates a failed primary authentication due to incorrect credentials. In contrast, 50057 means the account exists but is administratively disabled, so even a completely correct password would not allow sign-in. A brute-force attack using guessable passwords would almost exclusively produce 50126 events, not the disabled-account error code this query targets.

  • ✓

    Attempts to sign in with disabled user accounts.

    Why this is correct

    This is correct because Microsoft Entra ID returns ResultType 50057 specifically when a user attempts to sign in with an account that has been disabled by an administrator. The KQL query filtering on this ResultType will surface every such attempt, regardless of whether the provided password is accurate. Disabled accounts cannot authenticate at all, so these events represent a clear account-state failure rather than a credential mismatch.

  • ✗

    Brute force attacks from a single IP address against multiple accounts.

    Why it's wrong here

    While a single source IP attacking many accounts is a common brute-force pattern, this query's identifying power comes from ResultType 50057, not from the source IP. Brute force attempts against active accounts typically fail with 50126 (bad password) or 50053 (account locked), and only disabled accounts produce 50057. The query groups by user and IP to aggregate results, but the underlying condition is account state, so it cannot be characterized as a general brute-force detection.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.