Courseiva
Perform threat hunting →hardMultiple Choice

SC-200 Perform threat hunting Practice Question

Exhibit

Refer to the exhibit.
```kusto
// KQL query in Microsoft Sentinel hunting
let TargetUsers = dynamic(["admin@contoso.com", "user1@contoso.com"]);
SigninLogs
| where TimeGenerated > ago(7d)
| where UserPrincipalName in (TargetUsers)
| where RiskLevelDuringSignIn == "medium"
| project TimeGenerated, UserPrincipalName, IPAddress, RiskLevelDuringSignIn
| join kind=leftouter (
    AADServicePrincipalSignInLogs
    | where TimeGenerated > ago(7d)
    | project ServicePrincipalName, IPAddress
) on IPAddress
| summarize Count = count() by UserPrincipalName
| where Count > 5
```

You are reviewing a hunting query. What is the primary purpose of this query?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Find users with medium-risk sign-ins that share IP addresses with service principal sign-ins, indicating possible token theft or lateral movement

The query filters for users with medium risk sign-ins and joins with service principal sign-ins on IP address, then counts occurrences per user exceeding 5, indicating potential compromise involving both user and service principal activity from the same IP. Option A is wrong because it does not focus on service principal compromise alone. Option B is wrong because it does not look for admin consent grants. Option D is wrong because it uses only medium risk, not high.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    List all users with any risk level during sign-in in the last 7 days

    Why it's wrong here

    This option misstates the query's risk filter: the hunting query specifically filters for medium-risk sign-ins only, not any risk level. Moreover, the query aggregates and joins sign-in events with service principal sign-ins on IP address, so it is a correlation hunt rather than a simple listing of users. The goal is to surface shared-IP anomalies indicative of token theft, not to enumerate every risky user.

  • ✗

    Detect users who have granted admin consent to malicious OAuth apps

    Why it's wrong here

    The query contains no reference to OAuth consent grants, app role assignments, or admin consent events. To detect malicious admin consent, you would need to inspect the ConsentGrant table or audit logs for OAuth2 PermissionGrant events, which are entirely different telemetry sources. This option conflates application permissions with sign-in risk, whereas the query is focused on IP-based correlation between user and service principal sign-ins.

  • ✓

    Find users with medium-risk sign-ins that share IP addresses with service principal sign-ins, indicating possible token theft or lateral movement

    Why this is correct

    This option correctly describes the query's purpose: it starts with medium-risk user sign-ins, joins those with service principal sign-ins on the same IP address, and uses a count threshold to identify repeated correlation. Such a pattern can reveal token theft or lateral movement where an attacker uses a stolen user token from an IP also associated with a service principal. The combination of the risk level on the user sign-in and the shared IP with a service principal is the key investigative signal.

  • ✗

    Identify service principals that have been compromised and are performing high-risk sign-ins

    Why it's wrong here

    The query's primary entity is the user sign-in log; the risk level is applied to user sign-ins, not to service principal events. Although service principals appear in the join, the query does not assess whether the service principal itself is compromised or performing high-risk activity. Detecting compromised service principals would require separate anomaly or risk detections on the AADServicePrincipalSignInLogs table rather than a user-centric IP correlation.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.