SC-200 Perform threat hunting Practice Question
Which TWO tables in Microsoft Defender XDR advanced hunting provide information about user authentication events?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AADSignInEventsBeta
Option B (AADSignInEventsBeta) is correct because this table in Microsoft Defender XDR advanced hunting contains Microsoft Entra ID (Azure AD) sign-in events, including interactive and non-interactive user authentication activity such as successful and failed sign-ins. Option D (IdentityLogonEvents) is correct because it records authentication events across on-premises identity services, including Active Directory and other identity providers surfaced through Defender for Identity, capturing logon and authentication activity for user accounts. Option A (AlertInfo) is not correct because it stores metadata about generated alerts rather than raw authentication events. Option C (EmailEvents) is not correct because it holds email message and delivery information, not user sign-in data. Option E (DeviceNetworkEvents) is not correct because it contains network connection events from devices, not user authentication records.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AlertInfo
Why it's wrong here
AlertInfo returns alert metadata and detection records, not sign-in or authentication telemetry. It tempts because alerts often reference suspicious logons, but the authentication tables are AADSignInEventsBeta and IdentityLogonEvents, which hold the actual user authentication events.
- ✓
AADSignInEventsBeta
Why this is correct
AADSignInEventsBeta records Microsoft Entra ID sign-in events, capturing interactive and non-interactive authentication attempts with user, application, device and conditional access details. This directly satisfies the stem's requirement for user authentication data, complementing IdentityLogonEvents, which covers on-premises Active Directory authentication rather than cloud sign-ins.
- ✗
EmailEvents
Why it's wrong here
EmailEvents holds message-level metadata such as sender, recipient, delivery action and threat verdicts, so it records no sign-in or authentication activity. It is tempting because phishing investigations often begin with a suspicious message, and EmailEvents would be the right table for tracing delivery, URL clicks or attachment detonations — not for identifying authentication events.
- ✓
IdentityLogonEvents
Why this is correct
IdentityLogonEvents records authentication activity across on-premises Active Directory and Microsoft Entra ID, capturing sign-in attempts, account validation and logon failures. It directly satisfies the stem's requirement for user authentication events, unlike device, email or alert tables. Analysts query it to trace credential-based attacks and suspicious logons.
- ✗
DeviceNetworkEvents
Why it's wrong here
DeviceNetworkEvents records network connections, listening ports and remote IPs from Defender for Endpoint sensors, so it holds no authentication telemetry such as sign-in outcomes or MFA results. It is tempting because network data can hint at suspicious logons, and it would be the right choice when tracing outbound connections, C2 traffic or port activity on a device.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.