SC-200 Perform threat hunting Practice Question
Which TWO built-in Microsoft Sentinel hunting queries are useful for detecting signs of compromised credentials?
⚠ Common exam trap
SC-200 often tests whether candidates confuse persistence-related queries (new/deleted accounts) with credential compromise indicators (anomalous logon, brute force), so knowing the exact built-in query names and their purpose is essential.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anomalous logon location
Option B, 'Anomalous logon location,' is correct because it flags authentication events where a user signs in from an unusual or unexpected geographic location, which is a classic indicator that credentials have been stolen and are being used by an attacker from a different region. Option C, 'Brute force attempt against user accounts,' is correct because it detects repeated failed authentication attempts followed by a success, directly surfacing password-guessing activity that results in compromised credentials. Option A, 'Baseline of user behavior,' is a general behavioral analytics query that establishes normal activity patterns rather than specifically detecting credential compromise. Option D, 'Deleted user account,' relates to account lifecycle or destructive actions, not credential theft. Option E, 'New user account creation,' indicates persistence or privilege escalation via a newly created account, not the compromise of existing credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Baseline of user behavior
Why it's wrong here
Baseline of user behavior is not a predefined hunting query in Microsoft Sentinel; it describes the UEBA (User and Entity Behavior Analytics) concept where Sentinel learns normal patterns of user activity from Microsoft Entra ID, Microsoft 365, and other sources to spot deviations. While you could write a custom KQL query to compute baselines, it does not appear in the built-in hunting gallery, so it cannot be considered correct.
- ✓
Anomalous logon location
Why this is correct
Anomalous logon location is one of the built-in hunting queries in Microsoft Sentinel, found in the Hunting blade. It uses KQL to analyze sign-in logs, detecting attempts from unexpected geographies or IP addresses, which may indicate compromised credentials or impossible travel. This query is part of Sentinel's predefined hunting pack and is a strong indicator of credential misuse.
- ✓
Brute force attempt against user accounts
Why this is correct
Brute force attempt against user accounts is a built-in Microsoft Sentinel hunting query that detects a high number of failed sign-in attempts for a single user over a short time window. By grouping authentication logs (e.g., SigninLogs or SecurityEvent) and applying thresholds, it surfaces possible password-spraying or credential-stuffing attacks, aligning with MITRE ATT&CK technique T1110. This query is indeed included in Sentinel's hunting gallery.
- ✗
Deleted user account
Why it's wrong here
Deleted user account is not a built-in hunting query in Microsoft Sentinel because deletion alone is not a direct indicator of credential compromise; it is an administrative lifecycle event. While Microsoft Entra ID AuditLogs record deletions, Sentinel does not ship a predefined hunting query for this action, so it does not match the 'built-in' requirement for this question.
- ✗
New user account creation
Why it's wrong here
New user account creation is not one of the built-in Microsoft Sentinel hunting queries. Although attacker-created accounts can be a sign of persistence, a generic query for all new users would generate excessive noise because account creation is often legitimate. Sentinel therefore leaves this to custom detections via AuditLogs rather than providing a built-in hunting query, making this option incorrect.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.