SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit. ```kql SigninLogs | where TimeGenerated > ago(24h) | where ResultType == "0" | where AppDisplayName == "Office 365 Exchange Online" | summarize LoginCount = count() by UserPrincipalName, IPAddress | where LoginCount > 10 | project UserPrincipalName, IPAddress, LoginCount ```
You are analyzing sign-in logs in Microsoft Sentinel. The KQL query shown in the exhibit returns a list of users who have signed into Office 365 Exchange Online more than 10 times in the last 24 hours. You need to identify potential brute-force attacks. What additional information should you add to the query to improve detection?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Include both successful and failed sign-in attempts, then filter for users with a high number of failed attempts and at least one successful attempt.
To detect brute-force attacks, you need to look for multiple failed sign-in attempts followed by a success. The current query only shows successful sign-ins. Option A is correct because adding a condition to include failed attempts (ResultType != 0) and then filtering for users with many failures and at least one success would better indicate brute-force. Option B (changing the time window to 1 hour) may help detect rapid attempts but does not consider the success pattern. Option C (filtering by unusual geographic locations) may reduce false positives but does not directly detect brute-force. Option D (excluding users with MFA) is not relevant because MFA reduces risk but does not prevent brute-force detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Include both successful and failed sign-in attempts, then filter for users with a high number of failed attempts and at least one successful attempt.
Why this is correct
Brute-force detection requires correlating failures with eventual success, not just counting successful sign-ins. Including failed attempts and filtering for users with many failures plus at least one success exposes password-guessing that succeeded, which the current success-only query misses entirely.
- ✗
Change the time window to 1 hour to detect rapid attempts.
Why it's wrong here
Shortening the window to one hour changes the threshold's meaning rather than adding the failed-attempt and error-code data that distinguishes brute force from normal client reconnection. It is tempting because brute force is rapid, and a tighter window would be correct for detecting password-spray bursts within a defined period.
- ✗
Add a condition to only include sign-ins from unusual geographic locations.
Why it's wrong here
Geographic filtering alone flags impossible travel, not repeated authentication failures; brute-force detection needs ResultType and failure counts per account. It is tempting because unusual locations often accompany compromised credentials, and this condition would be correct for identifying anomalous sign-in origin during investigation.
- ✗
Add a condition to exclude users who have multi-factor authentication (MFA) enabled.
Why it's wrong here
Excluding MFA-enabled users removes the accounts whose successful sign-ins matter most, since brute-force detection hinges on failed attempts and anomalous success patterns, not MFA state. It is tempting because MFA reduces credential-theft risk, and filtering by authentication method would be correct when auditing legacy authentication exposure.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.