MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Cloud Apps. You need to generate a report of all external users who have shared sensitive files from SharePoint Online. Which feature should you use?
⚠ Common exam trap
Many exam-takers confuse the Activity log (which records user actions) with the App permissions report (which lists app-level permissions), leading them to select Option C when they need to track individual user sharing events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Activity log
The Activity log in Microsoft Defender for Cloud Apps captures detailed records of user activities across connected apps, including file-sharing events in SharePoint Online. By filtering the log for external users and sensitive file types, you can generate a precise report of external sharing activities. This is the correct feature because it directly records the specific actions needed for the report.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
OAuth app policies
Why it's wrong here
OAuth app policies in Defender for Cloud Apps are designed to govern and audit the permissions granted to third-party OAuth apps, such as mailbox access or calendar read, and to enforce conditional access controls on those apps. They do not capture or expose individual user actions like an external file share event; instead they focus on the consent grants and token usage of the apps themselves. Thus they cannot answer 'who shared what file externally' because that is an activity-level event, not an app-permission setting.
- ✓
Activity log
Why this is correct
The Defender for Cloud Apps activity log provides a comprehensive audit trail of user operations across connected cloud apps, including file-specific actions such as 'share file externally' and 'download file.' It supports granular filtering by user, IP address, device, and activity type, and you can specifically filter for activities where the target of the sharing is an external user. This makes it the definitive data source for investigating user file sharing, as it records both the actor and the action in near real-time. Alerts from these activities can also be routed to Microsoft Sentinel.
- ✗
App permissions report
Why it's wrong here
The App permissions report (often called the OAuth app permissions report) lists all OAuth-enabled apps in the tenant, along with the permissions each app has been granted and the users who approved those grants. It is used to identify overprivileged, unused, or risky apps that might have access to sensitive data, but it reflects only static consent grants, not the dynamic actions users perform like sharing a document with an external contact. Therefore, while it can indicate that an app has 'Read all files' permission, it cannot show that a specific user shared a specific file externally.
- ✗
Cloud Discovery
Why it's wrong here
Cloud Discovery is a Defender for Cloud Apps feature that ingests traffic logs from your network infrastructure (firewalls and proxies) to identify which cloud apps are in use, especially unsanctioned or 'shadow IT' apps. It focuses on app discovery, risk scoring, and usage statistics at the app level, not on per-user activity within a specific cloud service. Because it relies on network metadata rather than API connectors to cloud apps, it cannot report on granular actions such as an external file share inside Microsoft 365.
Go deeper
Related to this question
Learn chapter
Attack Simulation Training in Defender
Key term
SharePoint Online
SharePoint Online is a cloud-based collaboration platform from Microsoft that lets teams create, store, organize, and share content securely from anywhere.
Key term
External sharing
External sharing is the process of granting access to an organization's internal resources, such as documents or sites, to users who are not part of the organization's own identity system.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.