SC-200 Respond to security incidents Practice Question
A security analyst is investigating a potential data exfiltration incident in Microsoft Sentinel. The analyst needs to identify which users may have been compromised. Which THREE data sources should be queried to gather the most relevant evidence?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SigninLogs and AuditLogs from Microsoft Entra ID.
SigninLogs and AuditLogs from Microsoft Entra ID (C) are essential because SigninLogs reveal authentication anomalies such as impossible-travel or risky sign-ins tied to compromised accounts, while AuditLogs capture directory changes like new credentials or permission grants made by an attacker. OfficeActivity from Microsoft 365 (D) is correct because it records user and admin actions across Exchange, SharePoint, OneDrive, and Teams, exposing mail-forwarding rules, mass downloads, or file-sharing activity typical of exfiltration. CloudAppEvents from Microsoft Defender for Cloud Apps (E) is correct because it provides granular SaaS activity, including file downloads, uploads, and sharing events across connected cloud apps that reveal data movement. WindowsEvent from Defender for Endpoint (A) is endpoint telemetry focused on device-level process and file events, not user identity or cloud-service activity, so it is less directly relevant to identifying compromised users. AzureActivity from Azure Monitor (B) logs control-plane operations on Azure resources (e.g., role assignments, resource deployments) and does not capture the identity, mail, or SaaS activity needed here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WindowsEvent from Microsoft Defender for Endpoint.
Why it's wrong here
WindowsEvent captures endpoint OS events such as process creation and logons local to a device, not cloud identity authentication or mailbox access, so it cannot pinpoint which user accounts were compromised. Sign-in and audit logs are required. WindowsEvent would be correct when tracing malicious execution or persistence on a host.
- ✗
AzureActivity from Azure Monitor.
Why it's wrong here
AzureActivity records control-plane operations such as resource deployments and policy changes, not user sign-in or mailbox activity, so it cannot identify compromised accounts. Identity and email logs are needed. AzureActivity would be correct when investigating who modified or deleted Azure resources during an incident.
- ✓
SigninLogs and AuditLogs from Microsoft Entra ID.
Why this is correct
SigninLogs records authentication events and AuditLogs captures directory changes such as role assignments, consent grants and credential additions. Together they reveal anomalous sign-ins and privilege escalation tied to compromised accounts, satisfying the need to identify which users were affected.
- ✓
OfficeActivity from Microsoft 365.
Why this is correct
OfficeActivity provides unified audit log events for Exchange, SharePoint, OneDrive and Teams, exposing file downloads, sharing and mailbox rule creation. These actions evidence exfiltration by a compromised identity, directly addressing the requirement to identify affected users.
- ✓
CloudAppEvents from Microsoft Defender for Cloud Apps.
Why this is correct
CloudAppEvents from Microsoft Defender for Cloud Apps records user activity across sanctioned and unsanctioned cloud applications, including file downloads, sharing and anomalous access. It reveals which accounts performed suspicious cloud operations, directly supporting identification of compromised users during exfiltration investigations.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.