SC-200 Respond to security incidents Practice Question
You are investigating a brute force attack on a user account in Microsoft Entra ID. The sign-in logs show multiple failed attempts from different IP addresses. Which property in the sign-in logs indicates the type of authentication used?
⚠ Common exam trap
A common mix-up: candidates confuse `clientAppUsed` (which describes the application or client type) with the authentication method, but `clientAppUsed` only indicates the client software (e.g., 'Browser' or 'Mobile Apps and Desktop clients') and not the underlying authentication protocol or factor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
authenticationRequirement
The `authenticationRequirement` property in Microsoft Entra ID sign-in logs specifies the type of authentication used for the sign-in attempt, such as single-factor authentication (password), multi-factor authentication, or passwordless authentication. In a brute force attack investigation, this property helps determine whether the failed attempts were against password-based authentication or a more secure method, providing critical context for the attack vector.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
riskEventTypes
Why it's wrong here
The riskEventTypes property in the Microsoft Entra ID sign-in log enumerates specific risk detections identified by Identity Protection, such as impossible travel, anonymous IP address, or unfamiliar sign-in properties. These detections signal suspicious activity but do not describe the authentication strength used during the sign-in, such as whether MFA was required or satisfied. For a brute force investigation, you need to know the authentication method, not which risk event fired, so this field is not the correct one to inspect.
- ✗
conditionalAccessStatus
Why it's wrong here
conditionalAccessStatus indicates the result of applying Conditional Access policies to the sign-in, with possible values of success, failure, or notApplied, but it does not reveal the actual authentication type. Even if a policy requires MFA, the status field records whether access was granted or blocked, not whether the user authenticated with a password, a certificate, or a one-time code. Therefore, this property is about policy evaluation outcomes, not the strength of the credential used in the attack.
- ✗
clientAppUsed
Why it's wrong here
clientAppUsed identifies the application or client protocol that the user employed to access the service, such as Microsoft Entra Portal, IMAP4, POP3, or test123. For a legacy protocol like POP3, it may suggest that MFA can be bypassed because legacy protocols may not support MFA, but the field itself does not specify the authentication method or credential strength. The authentication requirement must be derived from a different property, so this field alone cannot answer whether MFA was used.
- ✓
authenticationRequirement
Why this is correct
authenticationRequirement is a sign-in log property that directly specifies the authentication strength required for the sign-in, such as singleFactorAuthentication or multiFactorAuthentication. In a brute force scenario, checking this field helps you determine whether the attacker only needed a valid password or whether they also had to satisfy an MFA challenge to succeed. This is the right field to inspect because it answers the exact question of which authentication type was used to access the account.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.