Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel. An incident is created from an Microsoft Entra ID (now Microsoft Entra ID) sign-in alert. You need to determine if the sign-in was from a compromised token. What data source should you examine?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sign-in logs in Microsoft Entra ID

Sign-in logs in Microsoft Entra ID contain detailed token information such as token issuer, session ID, and device details, which are essential for determining if a token was compromised. Option A is incorrect because audit logs track changes to directory objects, not sign-in details. Option B is incorrect because Azure Activity Log monitors Azure resource operations, not sign-in events. Option D is incorrect because Microsoft Defender for Cloud Apps logs focus on cloud application sessions and anomalies, but do not provide the granular sign-in token details found in sign-in logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Audit logs in Microsoft Entra ID

    Why it's wrong here

    Audit logs record directory configuration changes and administrative actions, not the token claims or sign-in telemetry needed to spot token theft. They are the right source for tracking who altered a conditional access policy or granted consent, but compromised-token detection requires the sign-in logs' token issuer and session details.

  • ✗

    Azure Activity Log

    Why it's wrong here

    Azure Activity Log records control-plane operations on Azure resources, such as who deployed or deleted a VM, and holds no Entra ID authentication telemetry. It would be the correct source when investigating suspicious resource modifications, but token compromise is an identity-plane event visible only in sign-in data.

  • ✓

    Sign-in logs in Microsoft Entra ID

    Why this is correct

    Sign-in logs record token issuance details, including the token's unique identifier and authentication context, letting you correlate the alert with the specific session and confirm whether a stolen or replayed token was used rather than legitimate credentials.

  • ✗

    Microsoft Defender for Cloud Apps logs

    Why it's wrong here

    Defender for Cloud Apps logs cover SaaS discovery, file activity and session controls after access is granted, not the Entra ID token issuance itself. It suits investigating anomalous cloud-app usage, yet determining whether a sign-in used a stolen token requires the sign-in logs' authentication and token details.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.