SC-200 Respond to security incidents Practice Question
You are investigating a security incident in Microsoft Sentinel. You need to identify which user account was used to perform a suspicious Azure Resource Manager operation that deleted a virtual machine. The operation was logged in Azure Activity logs. Which Kusto Query Language (KQL) query should you use to find the user identity associated with the deletion?
⚠ Common exam trap
The trap here is assuming that any log table containing 'Audit' or 'Activity' will have the needed data, without verifying the specific log source for Azure Resource Manager operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AzureActivity | where OperationName == 'Delete Virtual Machine' | project Caller
The AzureActivity table is the correct source for Azure Resource Manager operations, including VM deletions. The Caller field provides the identity of the user or service principal that performed the action. Filtering by OperationName ensures you isolate the deletion event. Other tables like SecurityEvent, SigninLogs, and AuditLogs do not contain ARM control plane operations, so they would not yield the required user identity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SecurityEvent | where Activity == 'Delete Virtual Machine' | project Account
Why it's wrong here
The SecurityEvent table contains Windows security events from virtual machines, not Azure Resource Manager operations. Azure VM deletion is an Azure control plane action logged in AzureActivity, not SecurityEvent. The Activity field also does not contain ARM operation names like 'Delete Virtual Machine', so this query would return no relevant results.
- ✓
AzureActivity | where OperationName == 'Delete Virtual Machine' | project Caller
Why this is correct
The AzureActivity table contains Azure Activity logs, including the Caller field which holds the user identity (UPN or object ID) that initiated the operation. Filtering by OperationName for 'Delete Virtual Machine' and projecting Caller directly returns the user account responsible, making this the correct and efficient query for the scenario.
- ✗
AuditLogs | where OperationName == 'Delete Virtual Machine' | project InitiatedBy
Why it's wrong here
AuditLogs in Microsoft Sentinel typically refers to Microsoft Entra ID audit logs, which cover directory changes like user creation or group membership, not Azure resource deletions. The InitiatedBy field is for Entra ID operations, not ARM. This query would not capture the VM deletion event, which is stored in AzureActivity.
- ✗
SigninLogs | where OperationName == 'Delete Virtual Machine' | project UserPrincipalName
Why it's wrong here
SigninLogs records interactive and non-interactive sign-in events, not resource management operations. The OperationName field in SigninLogs refers to sign-in operation types, not ARM actions. A VM deletion is an Azure Activity log event, so this query would not find the deletion operation or the user who performed it.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.