Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

While threat hunting in Microsoft Sentinel, you want to create a hunting query that identifies all attempts to disable security controls. Which data table would be most appropriate to query for such activity?

⚠ Common exam trap

The trap is confusing CommonSecurityLog (third-party CEF logs) with SecurityEvent (native Windows security logs); candidates often assume 'security' in the name means it holds all security events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SecurityEvent

The SecurityEvent table in Microsoft Sentinel contains Windows security events forwarded from agents, including Event ID 4688 (process creation) and events related to disabling security controls such as Windows Defender or audit policies. Threat hunting queries for control-disabling activity typically target SecurityEvent because it captures native Windows security log data. Other tables cover different log sources and would not contain these Windows security events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Syslog

    Why it's wrong here

    Syslog holds Linux and appliance event logs, not Microsoft 365 audit records where security-control disabling appears, so it cannot surface those attempts. It is tempting because Syslog captures system-level events, but the relevant audit trail lives in the Microsoft 365 Defender tables queried for such activity.

  • ✓

    SecurityEvent

    Why this is correct

    SecurityEvent captures Windows security auditing events, including modifications to security settings and attempts to disable controls such as Defender or audit policies. It is the appropriate table for hunting activity that weakens protective mechanisms across monitored machines.

  • ✗

    CommonSecurityLog

    Why it's wrong here

    CommonSecurityLog ingests third-party CEF appliance data, not native Microsoft Defender for Endpoint telemetry, so it lacks the security-control disabling events sought. It is tempting because it aggregates security events, but those originate from external devices rather than the Defender tables recording such changes.

  • ✗

    OfficeActivity

    Why it's wrong here

    OfficeActivity records user and admin actions in Microsoft 365 services such as Exchange and SharePoint, not endpoint security-control changes. It is tempting because disabling controls can involve admin activity, but Defender for Endpoint configuration changes appear in DeviceEvents, not OfficeActivity.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.