SC-200 Perform threat hunting Practice Question
You are a security analyst at Fabrikam. The company uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. During a threat hunt, you need to identify users who are accessing cloud applications from multiple geographic locations in a short time, which could indicate credential theft or token replay. You want to create a hunting query in Microsoft Sentinel using the CloudAppEvents table. Which approach should you take?
⚠ Common exam trap
The trap is that candidates pick OfficeActivity or SecurityAlert because they sound like they contain sign-in or location data, but only CloudAppEvents provides the enriched cloud app access telemetry with CountryCode needed for the multi-geo dcount pattern.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Query CloudAppEvents, summarize by AccountDisplayName and bin(TimeGenerated, 1h), then use dcount(CountryCode) > 1
The CloudAppEvents table in Microsoft Sentinel contains Microsoft Defender for Cloud Apps activity logs, including user sign-ins and access to cloud applications with geographic metadata such as CountryCode. Summarizing by AccountDisplayName and binning TimeGenerated into 1-hour windows, then filtering where dcount(CountryCode) > 1, directly detects the impossible-travel pattern described. This is the canonical KQL approach for multi-geo access hunting in Sentinel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Query CommonSecurityLog for VPN connections
Why it's wrong here
CommonSecurityLog holds VPN and firewall events, not the CloudAppEvents records of cloud app access the hunt requires, so geolocation across apps cannot be correlated. It is tempting because VPN logs do show source IPs, and would fit a hunt for suspicious remote network access rather than token replay in cloud services.
- ✗
Query OfficeActivity for sign-in logs
Why it's wrong here
OfficeActivity covers Microsoft 365 workloads only, so it cannot surface access across the broader cloud application estate the hunt targets. It is tempting because it does contain user sign-in and activity records, and would be the right table for hunting anomalies confined to Exchange, SharePoint or Teams.
- ✗
Query SecurityAlert for location-related alerts
Why it's wrong here
SecurityAlert holds generated alerts, not raw cloud-app access events, so it cannot correlate sign-in locations across users. It is tempting because location-based alerts exist, but CloudAppEvents is the table holding the raw activity needed for this hunting query.
- ✓
Query CloudAppEvents, summarize by AccountDisplayName and bin(TimeGenerated, 1h), then use dcount(CountryCode) > 1
Why this is correct
Summarising CloudAppEvents by AccountDisplayName within one-hour bins and filtering where dcount(CountryCode) exceeds one directly surfaces impossible-travel patterns, satisfying the requirement to detect users accessing cloud apps from multiple geographies in a short window. The CloudAppEvents table supplies the CountryCode and TimeGenerated fields this aggregation depends on.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.