Courseiva

SC-200 Respond to security incidents Practice Question

A security analyst receives a Microsoft Defender for Cloud Apps alert about a user performing unusual file downloads from SharePoint. The analyst needs to investigate the user's activity in the last 24 hours. Which log source should the analyst query first?

⚠ Common exam trap

It's easy for candidates to default to Office 365 audit logs (Option C) because they know SharePoint activity is logged there, but they miss that the alert is specifically from Defender for Cloud Apps, which has its own dedicated logs in Sentinel that are optimized for this investigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud App Security logs in Microsoft Sentinel

D is correct because Cloud App Security logs in Microsoft Sentinel provide the most granular and immediate visibility into user activities within Microsoft Defender for Cloud Apps, including file downloads from SharePoint. These logs capture detailed metadata such as file names, download counts, and user IP addresses, enabling the analyst to quickly identify anomalous behavior without needing to correlate across multiple data sources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra ID sign-in logs

    Why it's wrong here

    Microsoft Entra ID sign-in logs record authentication and authorization events, such as user-principal-name, IP address, and sign-in status rather than granular application interactions. A SharePoint file download occurs after authentication and is not represented as a distinct sign-in event, so these logs can't show which document was accessed. They are therefore unsuitable for identifying the specific file-download activity in this case.

  • ✗

    Microsoft Intune device logs

    Why it's wrong here

    Microsoft Intune device logs focus on device enrollment, compliance, configuration, and patching, and they do not audit user actions inside cloud workloads like SharePoint Online. A file download from SharePoint is a content-level event, not a device-management or health metric. These logs would not contain the file name, the user who performed the download, or the SharePoint site URL, making them useless for this investigation.

  • ✗

    Office 365 audit logs

    Why it's wrong here

    Office 365 audit logs (Unified audit log) can capture SharePoint file downloads and can be ingested into Microsoft Sentinel. However, when investigating a Defender for Cloud Apps event specifically, the dedicated CloudAppEvents log provides enriched metadata such as activity type, risk score, and app context without requiring cross-referencing across multiple workloads. Therefore, although audit logs are plausible, they are not the most focused or efficient source for this scenario.

  • ✓

    Cloud App Security logs in Microsoft Sentinel

    Why this is correct

    Microsoft Defender for Cloud Apps logs in Sentinel, specifically the CloudAppEvents table, provide a centralized, enriched record of user activities across cloud applications, including SharePoint Online file downloads. Each event includes the actor, target file, action, source IP, timestamp, and risk indicators. Because the analyst is investigating a Defender for Cloud Apps alert, these logs allow direct correlation of the file-download activity to the reported incident without relying on separate audit consoles.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.