Courseiva
Perform threat hunting →hardMultiple Select

Data Sources for Unusual Authentication Patterns in Microsoft Sentinel

Which THREE data sources can be used in Microsoft Sentinel for threat hunting to detect unusual authentication patterns? (Choose three.)

Quick Answer

The answer is SigninLogs, SecurityEvent, and AADNonInteractiveUserSignInLogs, as these three data sources in Microsoft Sentinel provide the authentication telemetry necessary for threat hunting to detect unusual authentication patterns. SigninLogs from Microsoft Entra ID capture interactive user sign-ins, including location, IP, and application details, while SecurityEvent (Windows Event Log) records local logon events like Event ID 4624, which is critical for spotting anomalous workstation or server access. AADNonInteractiveUserSignInLogs fill a crucial gap by logging service-side or script-based sign-ins that often bypass interactive logs, making them essential for detecting credential misuse in automated processes. On the SC-200 exam, this question tests your ability to distinguish authentication-specific sources from audit or network logs—a common trap is confusing OfficeActivity (which tracks user actions, not auth) or CommonSecurityLog (for firewall events) with actual sign-in data. Remember the mnemonic: “Three S’s for Sign-ins—SigninLogs, SecurityEvent, and Service-side (AADNonInteractive).”

⚠ Common exam trap

SC-200 often tests whether candidates can distinguish identity authentication tables (SigninLogs, AADNonInteractiveUserSignInLogs, SecurityEvent) from activity and network tables (OfficeActivity, CommonSecurityLog), so the trap is selecting OfficeActivity or CommonSecurityLog because they sound security-relevant when the question specifically asks about authentication patterns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SecurityEvent (Windows Event Logs)

Option A, SecurityEvent (Windows Event Logs), is correct because it ingests Windows security events such as 4624, 4625, and 4648, which reveal logon successes, failures, and explicit credential use that are essential for spotting unusual authentication patterns on hosts. Option B, AADNonInteractiveUserSignInLogs, is correct because it captures non-interactive Microsoft Entra ID sign-ins (token, service principal, and client-credential flows) that often indicate anomalous or automated authentication activity missed by interactive-only logs. Option E, SigninLogs (Microsoft Entra ID), is correct because it records interactive Entra ID sign-in events with details like IP address, location, device, conditional access result, and risk level, directly supporting detection of unusual authentication behavior. Option C, CommonSecurityLog, is not among the marked answers because it primarily carries CEF-formatted data from third-party security appliances (firewalls, proxies, IDS/IPS) rather than identity authentication telemetry. Option D, OfficeActivity (Office 365), is not among the marked answers because it focuses on Office 365 workload operations such as file, mailbox, and admin activities, not core authentication sign-in patterns.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SecurityEvent (Windows Event Logs)

    Why this is correct

    SecurityEvent carries Windows logon events, including 4624, 4625 and 4648, exposing failed logons, explicit credential use and unusual logon types. These fields let hunters detect anomalous authentication patterns across on-premises and domain-joined systems forwarded to Microsoft Sentinel.

  • ✓

    AADNonInteractiveUserSignInLogs

    Why this is correct

    AADNonInteractiveUserSignInLogs captures token issuance and refresh events without interactive user input, exposing anomalies such as impossible travel or suspicious service-principal activity. It satisfies the stem's unusual authentication patterns requirement by surfacing non-interactive sign-ins that interactive-only sources omit, feeding Microsoft Sentinel threat hunting queries.

  • ✗

    CommonSecurityLog

    Why it's wrong here

    CommonSecurityLog carries CEF-formatted events from third-party security appliances such as firewalls and proxies, not identity sign-in telemetry. It is tempting because it feeds many analytics rules, and would be correct for correlating network security events, but unusual authentication patterns require sign-in and audit logs.

  • ✗

    OfficeActivity (Office 365)

    Why it's wrong here

    OfficeActivity records user and admin actions within Microsoft 365 workloads such as SharePoint and Exchange, not Entra sign-in events. It tempts because it is a rich audit source, and would be correct for detecting anomalous file sharing or mailbox rule creation, but authentication anomalies need SigninLogs and AuditLogs.

  • ✓

    SigninLogs (Microsoft Entra ID)

    Why this is correct

    SigninLogs records Microsoft Entra ID interactive sign-ins with location, device, risk level and conditional access results. Hunters query it to spot anomalous authentication, such as impossible travel or unfamiliar sign-in properties, satisfying the requirement for authentication-focused hunting data.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which THREE data sources in Microsoft Sentinel are most useful for threat hunting activities related to identity compromise?

medium
  • ✓ A.SecurityEvent
  • ✓ B.SigninLogs
  • C.CommonSecurityLog
  • ✓ D.AuditLogs
  • E.OfficeActivity

Why A: SecurityEvent (A) is correct because it captures Windows Security event log data such as 4624/4625 logons, 4672 special privileges, and 4720/4728 account and group changes, which are essential for detecting credential theft, lateral movement, and privilege escalation tied to identity compromise. SigninLogs (B) is correct because it holds Microsoft Entra ID sign-in telemetry including result type, conditional access status, risk detections, IP/location, and MFA details, directly exposing brute-force, password spray, impossible travel, and token replay activity. AuditLogs (D) is correct because it records Entra ID directory changes such as role assignments, consent grants, credential additions, and user/group modifications that attackers use to persist or escalate after compromising an identity. CommonSecurityLog (C) is not among the correct answers because it carries third-party CEF/Syslog data (firewalls, proxies, IDS) rather than native identity authentication events. OfficeActivity (E) is not among the correct answers because it reflects Microsoft 365 workload operations (SharePoint, Exchange, Teams) and, while useful for post-compromise activity, is less directly focused on identity compromise than the authentication and directory sources.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.