SC-200 Perform threat hunting Practice Question
While threat hunting in Microsoft Sentinel, you want to create a hunting query that identifies all attempts to disable security controls. Which data table would be most appropriate to query for such activity?
⚠ Common exam trap
The trap is confusing CommonSecurityLog (third-party CEF logs) with SecurityEvent (native Windows security logs); candidates often assume 'security' in the name means it holds all security events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SecurityEvent
The SecurityEvent table in Microsoft Sentinel contains Windows security events forwarded from agents, including Event ID 4688 (process creation) and events related to disabling security controls such as Windows Defender or audit policies. Threat hunting queries for control-disabling activity typically target SecurityEvent because it captures native Windows security log data. Other tables cover different log sources and would not contain these Windows security events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Syslog
Why it's wrong here
Syslog holds Linux and appliance event logs, not Microsoft 365 audit records where security-control disabling appears, so it cannot surface those attempts. It is tempting because Syslog captures system-level events, but the relevant audit trail lives in the Microsoft 365 Defender tables queried for such activity.
- ✓
SecurityEvent
Why this is correct
SecurityEvent captures Windows security auditing events, including modifications to security settings and attempts to disable controls such as Defender or audit policies. It is the appropriate table for hunting activity that weakens protective mechanisms across monitored machines.
- ✗
CommonSecurityLog
Why it's wrong here
CommonSecurityLog ingests third-party CEF appliance data, not native Microsoft Defender for Endpoint telemetry, so it lacks the security-control disabling events sought. It is tempting because it aggregates security events, but those originate from external devices rather than the Defender tables recording such changes.
- ✗
OfficeActivity
Why it's wrong here
OfficeActivity records user and admin actions in Microsoft 365 services such as Exchange and SharePoint, not endpoint security-control changes. It is tempting because disabling controls can involve admin activity, but Defender for Endpoint configuration changes appear in DeviceEvents, not OfficeActivity.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.