You have a Microsoft Sentinel workspace collecting logs from 100 Windows Server virtual machines. To find failed sign-in (logon) events in the collected data, which table should you query?
Choose an answer
Tap an option to check your answer.
Correct answer: SecurityEvent.
Why this is the answer
The correct table to query for failed sign-in events from Windows Server virtual machines in Microsoft Sentinel is SecurityEvent. This table stores Windows security event logs, which include logon/logoff events (Event ID 4625 for failed logons). SigninLogs is incorrect because it primarily contains Azure Active Directory sign-in activity, not Windows Server local sign-in events. SecurityIncident is incorrect as it stores information about incidents detected by Sentinel, not raw security events. AuditLogs is incorrect because it typically contains Azure AD audit activity, such as changes made to Azure AD resources, not Windows Server logon events.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed