Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

While hunting, you notice a user account has been created and then immediately added to the Domain Admins group. Which table in Microsoft 365 Defender should you query to find this event?

⚠ Common exam trap

SC-200 often tests the confusion between IdentityLogonEvents (authentication) and IdentityDirectoryEvents (directory object changes) — candidates must remember that group membership changes are directory events, not logon events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IdentityDirectoryEvents

IdentityDirectoryEvents is the correct table because it records directory-service and identity-management events in Microsoft Defender XDR, including account creation, group membership changes, and role assignments such as adding a user to Domain Admins. This table captures the 'who did what to which identity object' details needed to hunt for privilege escalation via group membership. IdentityLogonEvents covers authentication activity, not directory object changes, so it would not show the group addition.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IdentityQueryEvents

    Why it's wrong here

    The IdentityQueryEvents table in Advanced Hunting records read-only operations, such as LDAP queries to Active Directory (for example, queries for group members or user attributes). While an adversary might query directory information for reconnaissance, these events do not log write operations or object creation; a newly created user account would not appear here because account creation is a modification event, not a query. Therefore this table won't show the actual creation or group membership change you discovered.

  • ✗

    IdentityLogonEvents

    Why it's wrong here

    IdentityLogonEvents captures authentication and sign-in activity, including successful and failed logons, session creation, and network sign-ins to domain resources, but it does not log changes to directory objects. The creation of a user account is an administrative update to Active Directory or Microsoft Entra ID and does not itself create a logon session; any subsequent authentication by that account is separate and would occur after the account exists. Thus this table is unsuitable when hunting for the account-creation event itself.

  • ✗

    DeviceEvents

    Why it's wrong here

    DeviceEvents is an endpoint-centric table in Advanced Hunting that includes operating system, process, file, and network events collected from devices via Microsoft Defender for Endpoint. Creating a user account is an identity-modification event that is audited at the directory level, not a device activity event that appears in this table; even if the creation command is executed on a device, the authoritative listing of the directory change resides in identity events, not DeviceEvents. Accordingly, you'd be querying the wrong data source for finding a new account.

  • ✓

    IdentityDirectoryEvents

    Why this is correct

    IdentityDirectoryEvents is the correct table because it contains audit records of directory service state changes, including user account creation, deletion, password resets, and group membership updates. When a user account appears in Active Directory or Microsoft Entra ID, the corresponding ActionType and target object details are logged here. This makes it the definitive source for hunting accounts that have been newly added or modified by an attacker.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.