SC-200 Respond to security incidents Practice Question
A SOC analyst needs to investigate a potential data exfiltration incident involving a user uploading files to an external cloud storage service. Which Microsoft Sentinel data source would provide the MOST relevant information?
⚠ Common exam trap
Candidates often confuse AzureActivity (resource management logs) with user activity logs, or assume SigninLogs contain file-level actions, when in fact only OfficeActivity provides the granular file upload events needed for data exfiltration investigations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
OfficeActivity
OfficeActivity (D) is the correct data source because it captures audit logs from Microsoft 365 services, including SharePoint Online, OneDrive for Business, and Exchange Online. These logs record file uploads, downloads, and sharing events, making them the most relevant for investigating data exfiltration to external cloud storage services like OneDrive or SharePoint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SigninLogs
Why it's wrong here
SigninLogs records authentication events, such as successful or failed sign-ins, with details like IP address, location, and user agent. It does not include any file operation data, so it cannot directly indicate whether files were uploaded or downloaded. While unusual sign-in patterns could suggest a compromised account, they do not provide the specific file-level evidence needed for a data exfiltration investigation.
- ✗
CommonSecurityLog
Why it's wrong here
CommonSecurityLog is a generic schema in Microsoft Sentinel that consolidates logs from firewalls, proxies, and other network security appliances. It typically contains network session metadata such as source/destination IPs, ports, and protocols, but it lacks application-level details for cloud services like SharePoint or OneDrive. Therefore, it would neither capture nor expose file upload or download actions performed by users in Microsoft 365.
- ✗
AzureActivity
Why it's wrong here
AzureActivity logs control-plane operations for Azure resources, such as virtual machine creation, configuration updates, or role assignments. It does not track data-plane events like file transfers or access to stored documents, which are the actual indicators of data exfiltration. As a result, querying this log would miss the exfiltration event entirely, even if a resource was used to stage or store stolen data.
- ✓
OfficeActivity
Why this is correct
OfficeActivity is the correct log because it captures detailed audit records from Microsoft 365, including SharePoint, OneDrive, Exchange, and Teams. It records data-plane events such as FileUploaded, FileDownloaded, and FileAccess, which are directly relevant to identifying data exfiltration. For instance, an analyst can search for a user downloading many documents from a sensitive SharePoint site or uploading content to an external location, making this the authoritative source for investigating file-based exfiltration.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.