Courseiva
Perform threat hunting →hardMultiple Choice

SC-200 Perform threat hunting Practice Question

Exhibit

Refer to the exhibit.
```kusto
IdentityLogonEvents
| where Timestamp > ago(14d)
| where AccountUpn endswith "@contoso.com"
| summarize LogonCount = count() by AccountUpn, IPAddress, Application
| where LogonCount == 1
| project AccountUpn, IPAddress, Application
```

You are analyzing the query above in Microsoft 365 Defender advanced hunting. The goal is to identify potentially compromised accounts used only once. The query returns thousands of results including many normal single logons. How can you refine the query to reduce false positives?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a filter to exclude IP addresses from the corporate VPN range and common applications like Outlook Web Access.

Adding a filter to exclude IP addresses from the corporate VPN range and common applications (like Outlook Web Access) helps reduce false positives by removing legitimate single logons that are expected. Option A (LogonCount > 1) would exclude the very accounts we are trying to find (single logons). Option B (removing the domain filter) would expand results but not necessarily reduce false positives. Option C (accounts never logged on before) is too restrictive and may miss compromised accounts used only once.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the where clause to LogonCount > 1.

    Why it's wrong here

    Filtering LogonCount > 1 returns accounts seen more than once, directly contradicting the goal of finding accounts used only once. It would suit hunting repeated or brute-force activity, but it eliminates precisely the single-use accounts the query must surface.

  • ✗

    Remove the filter on AccountUpn endswith "@contoso.com".

    Why it's wrong here

    Removing the domain filter widens the result set rather than narrowing it, so single-logon noise from external tenants increases. Domain scoping is genuinely useful when hunting only your own identities, but here it does not address the false-positive volume the stem describes.

  • ✗

    Add a filter to only include accounts that have never logged on before.

    Why it's wrong here

    First-seen accounts are common in tenant-to-tenant migrations and new hires, so this filter discards legitimate activity while retaining many single-logon false positives. Reducing noise requires correlating sign-in counts with risk signals such as impossible travel or unfamiliar user agents, not excluding new accounts.

  • ✓

    Add a filter to exclude IP addresses from the corporate VPN range and common applications like Outlook Web Access.

    Why this is correct

    Filtering out known-benign sources — corporate VPN egress addresses and common applications like Outlook Web Access — removes expected single logons, leaving anomalous ones. This directly targets the false-positive constraint by narrowing results to genuinely suspicious single-use accounts.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.