Courseiva
Perform threat hunting →mediumMultiple Select

SC-200 Perform threat hunting Practice Question

Which TWO tables in Microsoft Defender XDR advanced hunting provide information about user authentication events?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AADSignInEventsBeta

Option B (AADSignInEventsBeta) is correct because this table in Microsoft Defender XDR advanced hunting contains Microsoft Entra ID (Azure AD) sign-in events, including interactive and non-interactive user authentication activity such as successful and failed sign-ins. Option D (IdentityLogonEvents) is correct because it records authentication events across on-premises identity services, including Active Directory and other identity providers surfaced through Defender for Identity, capturing logon and authentication activity for user accounts. Option A (AlertInfo) is not correct because it stores metadata about generated alerts rather than raw authentication events. Option C (EmailEvents) is not correct because it holds email message and delivery information, not user sign-in data. Option E (DeviceNetworkEvents) is not correct because it contains network connection events from devices, not user authentication records.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AlertInfo

    Why it's wrong here

    AlertInfo returns alert metadata and detection records, not sign-in or authentication telemetry. It tempts because alerts often reference suspicious logons, but the authentication tables are AADSignInEventsBeta and IdentityLogonEvents, which hold the actual user authentication events.

  • ✓

    AADSignInEventsBeta

    Why this is correct

    AADSignInEventsBeta records Microsoft Entra ID sign-in events, capturing interactive and non-interactive authentication attempts with user, application, device and conditional access details. This directly satisfies the stem's requirement for user authentication data, complementing IdentityLogonEvents, which covers on-premises Active Directory authentication rather than cloud sign-ins.

  • ✗

    EmailEvents

    Why it's wrong here

    EmailEvents holds message-level metadata such as sender, recipient, delivery action and threat verdicts, so it records no sign-in or authentication activity. It is tempting because phishing investigations often begin with a suspicious message, and EmailEvents would be the right table for tracing delivery, URL clicks or attachment detonations — not for identifying authentication events.

  • ✓

    IdentityLogonEvents

    Why this is correct

    IdentityLogonEvents records authentication activity across on-premises Active Directory and Microsoft Entra ID, capturing sign-in attempts, account validation and logon failures. It directly satisfies the stem's requirement for user authentication events, unlike device, email or alert tables. Analysts query it to trace credential-based attacks and suspicious logons.

  • ✗

    DeviceNetworkEvents

    Why it's wrong here

    DeviceNetworkEvents records network connections, listening ports and remote IPs from Defender for Endpoint sensors, so it holds no authentication telemetry such as sign-in outcomes or MFA results. It is tempting because network data can hint at suspicious logons, and it would be the right choice when tracing outbound connections, C2 traffic or port activity on a device.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.