Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

You are a security analyst at Fabrikam. The company uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. During a threat hunt, you need to identify users who are accessing cloud applications from multiple geographic locations in a short time, which could indicate credential theft or token replay. You want to create a hunting query in Microsoft Sentinel using the CloudAppEvents table. Which approach should you take?

⚠ Common exam trap

The trap is that candidates pick OfficeActivity or SecurityAlert because they sound like they contain sign-in or location data, but only CloudAppEvents provides the enriched cloud app access telemetry with CountryCode needed for the multi-geo dcount pattern.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Query CloudAppEvents, summarize by AccountDisplayName and bin(TimeGenerated, 1h), then use dcount(CountryCode) > 1

The CloudAppEvents table in Microsoft Sentinel contains Microsoft Defender for Cloud Apps activity logs, including user sign-ins and access to cloud applications with geographic metadata such as CountryCode. Summarizing by AccountDisplayName and binning TimeGenerated into 1-hour windows, then filtering where dcount(CountryCode) > 1, directly detects the impossible-travel pattern described. This is the canonical KQL approach for multi-geo access hunting in Sentinel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Query CommonSecurityLog for VPN connections

    Why it's wrong here

    CommonSecurityLog holds VPN and firewall events, not the CloudAppEvents records of cloud app access the hunt requires, so geolocation across apps cannot be correlated. It is tempting because VPN logs do show source IPs, and would fit a hunt for suspicious remote network access rather than token replay in cloud services.

  • ✗

    Query OfficeActivity for sign-in logs

    Why it's wrong here

    OfficeActivity covers Microsoft 365 workloads only, so it cannot surface access across the broader cloud application estate the hunt targets. It is tempting because it does contain user sign-in and activity records, and would be the right table for hunting anomalies confined to Exchange, SharePoint or Teams.

  • ✗

    Query SecurityAlert for location-related alerts

    Why it's wrong here

    SecurityAlert holds generated alerts, not raw cloud-app access events, so it cannot correlate sign-in locations across users. It is tempting because location-based alerts exist, but CloudAppEvents is the table holding the raw activity needed for this hunting query.

  • ✓

    Query CloudAppEvents, summarize by AccountDisplayName and bin(TimeGenerated, 1h), then use dcount(CountryCode) > 1

    Why this is correct

    Summarising CloudAppEvents by AccountDisplayName within one-hour bins and filtering where dcount(CountryCode) exceeds one directly surfaces impossible-travel patterns, satisfying the requirement to detect users accessing cloud apps from multiple geographies in a short window. The CloudAppEvents table supplies the CountryCode and TimeGenerated fields this aggregation depends on.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.