Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

Exhibit

Refer to the exhibit.

```kql
let TargetUser = 'jdoe@contoso.com';
IdentityLogonEvents
| where Timestamp > ago(7d)
| where AccountUpn == TargetUser
| where Application == 'Azure Portal'
| summarize LogonCount = count() by IPAddress, Country
| where LogonCount > 10
```

Refer to the exhibit. You are investigating a user account that shows multiple logons to the Azure Portal from various countries within a short time. The query returns no results despite known logons. What is the most likely issue?

⚠ Common exam trap

SC-200 often tests the distinction between on-premises identity tables (IdentityLogonEvents) and cloud identity tables (AADSignInEventsBeta), so candidates who assume all logon events are in one table pick the wrong filter or field.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IdentityLogonEvents does not contain Azure Portal logon events; use AADSignInEventsBeta instead.

IdentityLogonEvents in Microsoft Defender for Identity (MDI) captures on-premises Active Directory authentication events, not Microsoft Entra ID (Entra ID) sign-in events. Azure Portal logons are Microsoft Entra ID sign-in events, which are stored in the AADSignInEventsBeta table in Microsoft 365 Defender advanced hunting. Therefore, querying IdentityLogonEvents for Azure Portal logons returns no results, and the correct table is AADSignInEventsBeta.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Timestamp filter should be Timestamp > ago(7d) but instead it's written incorrectly.

    Why it's wrong here

    A malformed ago() expression would trigger a syntax error rather than silently return zero rows, and the exhibit's timestamp filter is valid. Correcting time-range syntax is the right fix when the query itself fails to parse or when the window genuinely excludes the events being investigated.

  • ✗

    The AccountUpn field is not present in IdentityLogonEvents.

    Why it's wrong here

    IdentityLogonEvents does include the AccountUpn column, so its absence cannot explain the empty result set. This field is the correct one to filter on when correlating sign-in activity to a specific user across Microsoft Defender for Identity and Entra ID data.

  • ✗

    The Application filter should be 'Azure Portal' in a different case.

    Why it's wrong here

    KQL is case-insensitive.

  • ✓

    IdentityLogonEvents does not contain Azure Portal logon events; use AADSignInEventsBeta instead.

    Why this is correct

    IdentityLogonEvents captures only on-premises Active Directory and AD FS authentication, not cloud sign-ins. Azure Portal logons are recorded in Microsoft Entra ID sign-in logs, surfaced in Microsoft Defender for Cloud Apps through the AADSignInEventsBeta table. Querying the wrong table explains the empty result despite known portal logons.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.