Microsoft Security Operations Analyst Associate SC-200 Practice Question
You are investigating a suspected account compromise for a user in your tenant. To review the user's interactive sign-in events from the last 24 hours, you decide to query Microsoft Graph. Which REST endpoint should you call so that the results include only that user's sign-ins within the required time range?
Azure AD sign-in events are stored under the Microsoft Graph auditLogs namespace. Interactive sign-ins can be retrieved by calling /auditLogs/signIns and filtering with the user's object ID (userId) together with a createdDateTime range. The other listed endpoints surface security alerts, risk detections, or Microsoft 365 activity data-none of which return the raw sign-in log entries needed for authentication investigations.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Microsoft Graph?
Open an interactive chat with Bash
What is an ISO-8601 timestamp?
Open an interactive chat with Bash
What is the auditLogs/signIns endpoint, and how does it work?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .