SC-200 Perform threat hunting Practice Question
Your threat hunting hypothesis is that a user's credentials were used to sign in from two geographically distant locations within a short time. In Microsoft Defender for Cloud Apps, which log type would you query in Microsoft Sentinel to detect impossible travel?
⚠ Common exam trap
The trap is confusing sign-in telemetry with activity telemetry — candidates may pick OfficeActivity because the user 'did something,' but impossible travel specifically requires sign-in geolocation data, which lives in SigninLogs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SigninLogs
Impossible travel detection relies on analyzing sign-in events with their source IP geolocation and timestamps. In Microsoft Sentinel, Microsoft Entra ID (Entra ID) sign-in events are stored in the SigninLogs table, which contains fields like IPAddress, Location, and TimeGenerated needed to compute whether a user signed in from two distant locations within an implausible timeframe. Defender for Cloud Apps surfaces these as impossible travel alerts, but the underlying Sentinel query targets SigninLogs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SigninLogs
Why this is correct
SigninLogs in Microsoft Sentinel records Microsoft Entra ID sign-in events with IP-derived location and timestamp data. Querying it lets you correlate two authentications from geographically distant locations within an implausible interval, directly testing the impossible travel hypothesis.
- ✗
AuditLogs
Why it's wrong here
AuditLogs records administrative and service activity, not interactive user sign-ins, so impossible travel cannot be detected there. Sign-in events with location and IP data live in SigninLogs. AuditLogs would be correct when investigating configuration changes, consent grants or other tenant-level administrative actions.
- ✗
CommonSecurityLog
Why it's wrong here
CommonSecurityLog ingests CEF-formatted events from third-party security appliances, so it holds no Microsoft Entra ID sign-in records with source IP geolocation. It is tempting because it is the generic security-events table, and it would be correct for correlating firewall or proxy logs from non-Microsoft devices.
- ✗
OfficeActivity
Why it's wrong here
OfficeActivity records SharePoint, Exchange and Teams audit events, not interactive sign-in telemetry, so impossible-travel geolocation cannot be derived from it. It is tempting because OfficeActivity does surface user activity, and it would be the right table for auditing file downloads or mailbox rule changes rather than sign-in anomalies.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.