Courseiva

SC-200 Respond to security incidents Practice Question

A SOC analyst is investigating an incident where a user's credentials were compromised. The analyst uses Microsoft Sentinel to find all activities performed by the user in the last 24 hours. Which data source should the analyst query FIRST to get the most comprehensive view of the user's actions across Microsoft 365?

⚠ Common exam trap

It's easy for candidates to choose SigninLogs (Option D) thinking it covers all user actions, but it only shows authentication events, not the actual activities performed after sign-in, which is a common misconception tested in SC-200.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

OfficeActivity

OfficeActivity (Option B) is the correct first query because it captures user actions across Exchange Online, SharePoint Online, OneDrive for Business, Teams, and other Microsoft 365 workloads via the unified audit log. This provides the most comprehensive view of a user's activities—including email sends, file accesses, and Teams messages—within the last 24 hours, which is essential for investigating compromised credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceEvents

    Why it's wrong here

    DeviceEvents in Microsoft 365 Defender's Advanced Hunting captures endpoint-level activities such as process creations, file system changes, and registry modifications. It does not contain user actions occurring within Microsoft 365 apps like SharePoint, Exchange, or Teams, so it would be irrelevant when investigating a user's cloud-based activities. For this incident, DeviceEvents offers no insight into the user's M365 actions.

  • ✓

    OfficeActivity

    Why this is correct

    OfficeActivity represents the unified audit log for Microsoft 365, pulling records from Exchange, SharePoint, OneDrive, Teams, and other workloads. It captures user-level events such as email actions, file accesses, and messages sent after authentication, making it the appropriate table to investigate a user's activities in M365. This table is the primary source for reconstructing user behavior in the M365 environment.

  • ✗

    AzureActivity

    Why it's wrong here

    AzureActivity contains resource management-plane logs for Azure, including events like VM start/stop, role assignments, and deployment configurations. These activities relate to Azure infrastructure, not user interactions within Microsoft 365 productivity services. Since the incident involves user activity in M365, AzureActivity would provide no relevant data about actions taken in SharePoint or Exchange.

  • ✗

    SigninLogs

    Why it's wrong here

    SigninLogs records authentication events in Microsoft Entra ID, including sign-in success/failure, used application, IP address, and multi-factor authentication result. However, it stops at the moment the user is authenticated and does not detail what the user did after signing in, such as downloading files or sending emails. Therefore, while it may help confirm a sign-in, it cannot show the actual user actions required for this investigation.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A SOC analyst needs to investigate a potential data exfiltration incident involving a user uploading files to an external cloud storage service. Which Microsoft Sentinel data source would provide the MOST relevant information?

easy
  • A.SigninLogs
  • B.CommonSecurityLog
  • C.AzureActivity
  • ✓ D.OfficeActivity

Why D: OfficeActivity (D) is the correct data source because it captures audit logs from Microsoft 365 services, including SharePoint Online, OneDrive for Business, and Exchange Online. These logs record file uploads, downloads, and sharing events, making them the most relevant for investigating data exfiltration to external cloud storage services like OneDrive or SharePoint.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.