Courseiva

SC-200 Respond to security incidents Practice Question

You are investigating a security incident in Microsoft Sentinel. You need to identify which user account was used to perform a suspicious Azure Resource Manager operation that deleted a virtual machine. The operation was logged in Azure Activity logs. Which Kusto Query Language (KQL) query should you use to find the user identity associated with the deletion?

⚠ Common exam trap

The trap here is assuming that any log table containing 'Audit' or 'Activity' will have the needed data, without verifying the specific log source for Azure Resource Manager operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AzureActivity | where OperationName == 'Delete Virtual Machine' | project Caller

The AzureActivity table is the correct source for Azure Resource Manager operations, including VM deletions. The Caller field provides the identity of the user or service principal that performed the action. Filtering by OperationName ensures you isolate the deletion event. Other tables like SecurityEvent, SigninLogs, and AuditLogs do not contain ARM control plane operations, so they would not yield the required user identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SecurityEvent | where Activity == 'Delete Virtual Machine' | project Account

    Why it's wrong here

    The SecurityEvent table contains Windows security events from virtual machines, not Azure Resource Manager operations. Azure VM deletion is an Azure control plane action logged in AzureActivity, not SecurityEvent. The Activity field also does not contain ARM operation names like 'Delete Virtual Machine', so this query would return no relevant results.

  • ✓

    AzureActivity | where OperationName == 'Delete Virtual Machine' | project Caller

    Why this is correct

    The AzureActivity table contains Azure Activity logs, including the Caller field which holds the user identity (UPN or object ID) that initiated the operation. Filtering by OperationName for 'Delete Virtual Machine' and projecting Caller directly returns the user account responsible, making this the correct and efficient query for the scenario.

  • ✗

    AuditLogs | where OperationName == 'Delete Virtual Machine' | project InitiatedBy

    Why it's wrong here

    AuditLogs in Microsoft Sentinel typically refers to Microsoft Entra ID audit logs, which cover directory changes like user creation or group membership, not Azure resource deletions. The InitiatedBy field is for Entra ID operations, not ARM. This query would not capture the VM deletion event, which is stored in AzureActivity.

  • ✗

    SigninLogs | where OperationName == 'Delete Virtual Machine' | project UserPrincipalName

    Why it's wrong here

    SigninLogs records interactive and non-interactive sign-in events, not resource management operations. The OperationName field in SigninLogs refers to sign-in operation types, not ARM actions. A VM deletion is an Azure Activity log event, so this query would not find the deletion operation or the user who performed it.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.