SC-200 Perform threat hunting Practice Question
You are hunting for privileged account abuse in Microsoft Entra ID. Which table in Microsoft Sentinel contains audit logs for changes to directory roles?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AuditLogs
AuditLogs in Microsoft Sentinel contain audit data from Microsoft Entra ID, including changes to directory roles. Option A (IdentityLogonEvents) is incorrect as it contains identity protection events. Option C (SigninLogs) is incorrect because it contains user sign-in events. Option D (DeviceLogonEvents) is incorrect as it logs device logon events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IdentityLogonEvents
Why it's wrong here
IdentityLogonEvents records authentication events from Entra ID, Active Directory and Okta, capturing sign-in and logon activity rather than directory role changes. It is tempting because privileged abuse often surfaces through suspicious logons, and this table would be the right choice when correlating failed authentications or anomalous sign-ins to compromised accounts.
- ✓
AuditLogs
Why this is correct
AuditLogs records Microsoft Entra ID directory activity, including role membership and role definition changes, so it directly satisfies the requirement to hunt privileged account abuse through directory role modifications. SigninLogs covers authentication events instead, not administrative role changes.
- ✗
SigninLogs
Why it's wrong here
SigninLogs records authentication events — sign-in attempts, conditional access outcomes and risk detections — not directory role assignment changes. It is tempting because privileged abuse often surfaces as anomalous sign-ins, and SigninLogs would be the correct table for investigating risky or failed authentication attempts against privileged accounts.
- ✗
DeviceLogonEvents
Why it's wrong here
DeviceLogonEvents records endpoint sign-in activity from Defender for Endpoint, covering interactive and remote logons on devices, not directory role changes in Microsoft Entra ID. It is tempting because logon telemetry does surface credential misuse, and it would be the right table when investigating suspicious interactive or network logons on a specific host.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.