Courseiva

SC-200 Respond to security incidents Practice Question

A security analyst in your SOC receives an alert from Microsoft Defender for Cloud Apps indicating that a user downloaded a large number of files from SharePoint in a short time. What is the most likely classification of this activity?

⚠ Common exam trap

Many candidates confuse bulk file downloads with ransomware activity (Option A) because both involve unusual file operations, but ransomware focuses on encryption/modification, not exfiltration, and Defender for Cloud Apps has separate detections for each behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data exfiltration

A sudden, large-volume download of files from SharePoint within a short time window is a classic indicator of data exfiltration. Microsoft Defender for Cloud Apps uses anomaly detection policies to flag such activity based on user baseline behavior, download velocity, and the total number of files accessed, which aligns with the exfiltration phase of the cyber kill chain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ransomware

    Why it's wrong here

    This behavior is inconsistent with ransomware because no cryptographic file modifications, common ransomware extensions, or ransom notes were observed. Ransomware typically encrypts or locks local files and demands payment, whereas downloading many files suggests copying data out rather than destroying or holding it. Without those ransomware indicators, this alert is more likely associated with data theft.

  • ✗

    Lateral movement

    Why it's wrong here

    Lateral movement requires actions such as remote authentication, credential reuse, SMB/PsExec execution, or RDP connections to other hosts. The observed activity is centered on downloading many files from a single source, which does not demonstrate any attempt to pivot, execute remote commands, or expand access across the network. Therefore, this is not a valid classification for this alert.

  • ✓

    Data exfiltration

    Why this is correct

    Bulk downloading many files from a host, especially under a security alert, strongly indicates that an attacker is collecting and removing sensitive data. This aligns with the MITRE ATT&CK exfiltration technique (TA0010), where data is transferred out of the environment via HTTP/S, cloud storage, email, or removable media. The volume and pattern of file downloads make data exfiltration the most reasonable and supported conclusion.

  • ✗

    Privilege escalation

    Why it's wrong here

    Privilege escalation would require evidence of permission changes, token manipulation, UAC bypass, or the creation of accounts with elevated rights. None of these indicators are present in the described alert, and the act of downloading files does not require elevated privileges. The alert reflects theft of data rather than an attempt to gain additional access or permissions within the system.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.