Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

You are hunting for privileged account abuse in Microsoft Entra ID. Which table in Microsoft Sentinel contains audit logs for changes to directory roles?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AuditLogs

AuditLogs in Microsoft Sentinel contain audit data from Microsoft Entra ID, including changes to directory roles. Option A (IdentityLogonEvents) is incorrect as it contains identity protection events. Option C (SigninLogs) is incorrect because it contains user sign-in events. Option D (DeviceLogonEvents) is incorrect as it logs device logon events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IdentityLogonEvents

    Why it's wrong here

    IdentityLogonEvents records authentication events from Entra ID, Active Directory and Okta, capturing sign-in and logon activity rather than directory role changes. It is tempting because privileged abuse often surfaces through suspicious logons, and this table would be the right choice when correlating failed authentications or anomalous sign-ins to compromised accounts.

  • ✓

    AuditLogs

    Why this is correct

    AuditLogs records Microsoft Entra ID directory activity, including role membership and role definition changes, so it directly satisfies the requirement to hunt privileged account abuse through directory role modifications. SigninLogs covers authentication events instead, not administrative role changes.

  • ✗

    SigninLogs

    Why it's wrong here

    SigninLogs records authentication events — sign-in attempts, conditional access outcomes and risk detections — not directory role assignment changes. It is tempting because privileged abuse often surfaces as anomalous sign-ins, and SigninLogs would be the correct table for investigating risky or failed authentication attempts against privileged accounts.

  • ✗

    DeviceLogonEvents

    Why it's wrong here

    DeviceLogonEvents records endpoint sign-in activity from Defender for Endpoint, covering interactive and remote logons on devices, not directory role changes in Microsoft Entra ID. It is tempting because logon telemetry does surface credential misuse, and it would be the right table when investigating suspicious interactive or network logons on a specific host.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.