SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Exhibit
Refer to the exhibit.
```kql
// Microsoft Sentinel KQL query
let timeframe = 7d;
IdentityLogonEvents
| where Timestamp > ago(timeframe)
| where Application == "Microsoft Teams"
| summarize LogonAttempts = count() by UserPrincipalName, IPAddress
| where LogonAttempts > 10
| join kind=inner (
AADNonInteractiveUserSignInLogs
| where Timestamp > ago(timeframe)
| summarize FailedSignIns = count() by UserPrincipalName
) on UserPrincipalName
| project UserPrincipalName, IPAddress, LogonAttempts, FailedSignIns
| order by FailedSignIns desc
```You are reviewing a Microsoft Sentinel KQL query. What is the primary purpose of this query?
```kql SigninLogs | where TimeGenerated > ago(7d) | where AppDisplayName == "Microsoft Teams" | summarize TotalAttempts = count(), FailedAttempts = countif(ResultType != 0) by UserPrincipalName | where TotalAttempts > 10 and FailedAttempts > 5 | project UserPrincipalName, TotalAttempts, FailedAttempts ```
⚠ Common exam trap
A common trap is confusing brute-force detection with account compromise detection. This query focuses on high failed sign-ins combined with high overall attempts, which points to brute force, not to successful logon anomalies, global admin role checks, or conditional access policy evaluation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify users with high logon attempts to Teams and high failed sign-ins, possibly indicating a brute-force attack
The query filters Microsoft Teams sign-ins from the last 7 days, aggregates total and failed sign-in attempts per user, and returns users with more than 10 total attempts and more than 5 failed attempts. This pattern of high volume and repeated failure is indicative of a brute-force attack, making option B correct. The query does not filter for global administrator role or conditional access policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identify all users who have attempted to log on to Microsoft Teams more than 10 times in the last 7 days and who are global administrators
Why it's wrong here
Typical KQL queries against the `SigninLogs` table primarily focus on authentication events and their outcomes. While `SigninLogs` contains user principal names, it does not inherently include information about a user's administrative roles, such as Global Administrator. To filter by admin roles, the query would require joining with other data sources like `IdentityInfo` or `AzureActivity` that contain role assignment details, which is not implied by a basic sign-in attempt analysis.
- ✓
Identify users with high logon attempts to Teams and high failed sign-ins, possibly indicating a brute-force attack
Why this is correct
This option accurately describes a common security analysis scenario. A KQL query designed to identify users with a high total number of logon attempts to Microsoft Teams, coupled with a significant count of failed sign-ins for the same user, strongly indicates a potential brute-force attack. This correlation is crucial as it highlights malicious actors repeatedly trying to guess credentials, distinguishing it from legitimate user errors or occasional failed attempts.
- ✗
Identify users with high failed sign-ins and check if they have conditional access policies applied
Why it's wrong here
A standard KQL query analyzing `SigninLogs` for failed attempts does not inherently provide granular details about the Conditional Access policies applied to those specific sign-ins. While `SigninLogs` can indicate if a Conditional Access policy was evaluated or blocked a sign-in (e.g., via `ConditionalAccessStatus`), it does not typically enumerate the specific policies or their configurations. Retrieving comprehensive policy details would necessitate querying or joining with `AADConditionalAccessPolicy` or related tables, which is not part of a basic sign-in analysis.
- ✗
Identify users with high successful logon attempts to Teams and correlate with failed sign-ins to detect account compromise
Why it's wrong here
A query focused on "high logon attempts" typically aggregates all sign-in attempts, irrespective of their success or failure. To specifically identify "high successful logon attempts" for correlation with failed sign-ins, the KQL query would need to explicitly filter the `ResultType` field for successful authentications (e.g., `ResultType == 0`). Without this specific filter, the query would count both successful and failed attempts together, preventing the precise correlation required to detect account compromise based on successful logons.
Go deeper
Related to this question
Learn chapter
Microsoft Entra Access Reviews
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Role
A role is a named set of permissions that can be assigned to users or groups to control access to resources in an IT environment.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.