SC-200 Perform threat hunting Practice Question
You are investigating a series of failed logon attempts across multiple on-premises servers. You want to use Microsoft Sentinel to hunt for patterns of brute-force attacks. Which data source should you ingest to capture detailed authentication events from domain controllers?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Security Events via Windows Event Forwarding
Windows Security Events from domain controllers, collected via Windows Event Forwarding (WEF) or directly, include Event ID 4625 (failed logon) and other authentication events necessary for brute-force hunting. Option A is incorrect because Syslog from domain controllers does not capture Windows Security Events; Syslog is typically used for network devices or Linux systems. Option C is incorrect because Azure Activity Log records Azure resource management operations, not on-premises authentication events. Option D is incorrect because Microsoft 365 Defender events cover cloud and endpoint alerts but not detailed authentication logs from on-premises domain controllers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Syslog from domain controllers
Why it's wrong here
Domain controllers do not emit native syslog (RFC 3164/5424); they write authentication events such as Event ID 4625 as structured entries in the Windows Security Event Log. You could install a third-party agent or syslog-forwarder to translate those security events, but that would be a separate delivery mechanism and would lose field fidelity and reliability compared with native Windows Event Forwarding. Thus, treating 'syslog from domain controllers' as a direct source is incorrect for this investigation.
- ✓
Windows Security Events via Windows Event Forwarding
Why this is correct
Windows Security Events, collected via Windows Event Forwarding (WEF), are the authoritative source for on-premises failed-logon hunting because domain controllers log Event ID 4625 for every failed NTLM/Kerberos logon attempt. WEF uses HTTP/HTTPS (WinRM) and a collector-initiated subscription, preserving the full payload: source IP address, workstation name, logon type, and authentication package. This enables centralized correlation across all DCs in the domain and direct ingestion into a SIEM such as Sentinel.
- ✗
Azure Activity Log
Why it's wrong here
The Azure Activity Log (now the Azure Monitor activity log) records control-plane operations on Azure resources—like creating virtual machines, modifying NSG rules, or assigning RBAC roles—not interactive authentication attempts. On-premises domain-controller failed logons never appear in it, and even Microsoft Entra ID user sign-ins would require the separate 'Sign-ins' log under Microsoft Entra ID, not the Activity Log. Therefore, it cannot provide any 4625-like failure data for this scenario.
- ✗
Microsoft 365 Defender events
Why it's wrong here
Microsoft 365 Defender (M365D) is an XDR portal that correlates cloud identity, email, and endpoint signals; any on-premises AD visibility it has comes from Defender for Identity sensors that read the DC's Windows Event Log indirectly. It does not expose the raw, complete Security Event 4625 records needed for a full custom brute-force analysis, and it is not the original source of those events. Use WEF-collected Security Events as the ground truth; M365D could supplement analyst insight but not replace raw event collection.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.