Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

Refer to the exhibit.

```kql
SigninLogs
| where TimeGenerated > ago(24h)
| where ResultType == "0"
| where AppDisplayName == "Office 365 Exchange Online"
| summarize LoginCount = count() by UserPrincipalName, IPAddress
| where LoginCount > 10
| project UserPrincipalName, IPAddress, LoginCount
```

You are analyzing sign-in logs in Microsoft Sentinel. The KQL query shown in the exhibit returns a list of users who have signed into Office 365 Exchange Online more than 10 times in the last 24 hours. You need to identify potential brute-force attacks. What additional information should you add to the query to improve detection?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Include both successful and failed sign-in attempts, then filter for users with a high number of failed attempts and at least one successful attempt.

To detect brute-force attacks, you need to look for multiple failed sign-in attempts followed by a success. The current query only shows successful sign-ins. Option A is correct because adding a condition to include failed attempts (ResultType != 0) and then filtering for users with many failures and at least one success would better indicate brute-force. Option B (changing the time window to 1 hour) may help detect rapid attempts but does not consider the success pattern. Option C (filtering by unusual geographic locations) may reduce false positives but does not directly detect brute-force. Option D (excluding users with MFA) is not relevant because MFA reduces risk but does not prevent brute-force detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Include both successful and failed sign-in attempts, then filter for users with a high number of failed attempts and at least one successful attempt.

    Why this is correct

    Brute-force detection requires correlating failures with eventual success, not just counting successful sign-ins. Including failed attempts and filtering for users with many failures plus at least one success exposes password-guessing that succeeded, which the current success-only query misses entirely.

  • ✗

    Change the time window to 1 hour to detect rapid attempts.

    Why it's wrong here

    Shortening the window to one hour changes the threshold's meaning rather than adding the failed-attempt and error-code data that distinguishes brute force from normal client reconnection. It is tempting because brute force is rapid, and a tighter window would be correct for detecting password-spray bursts within a defined period.

  • ✗

    Add a condition to only include sign-ins from unusual geographic locations.

    Why it's wrong here

    Geographic filtering alone flags impossible travel, not repeated authentication failures; brute-force detection needs ResultType and failure counts per account. It is tempting because unusual locations often accompany compromised credentials, and this condition would be correct for identifying anomalous sign-in origin during investigation.

  • ✗

    Add a condition to exclude users who have multi-factor authentication (MFA) enabled.

    Why it's wrong here

    Excluding MFA-enabled users removes the accounts whose successful sign-ins matter most, since brute-force detection hinges on failed attempts and anomalous success patterns, not MFA state. It is tempting because MFA reduces credential-theft risk, and filtering by authentication method would be correct when auditing legacy authentication exposure.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.