Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

A threat hunter is investigating a potential malware outbreak in Microsoft Defender for Cloud Apps. The hunter notices that multiple users have installed a new app with high permissions that accesses their email. The app was not requested by IT. What is the most effective way to hunt for all instances of this app across the organization?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the Cloud App Security activity log to search for 'Install app' events and then review the 'App governance' dashboard for all instances

The activity log in Cloud App Security provides a comprehensive record of app installation events, and the App Governance dashboard aggregates all instances for review, making it the most effective hunting approach. Option A (conditional access policies) is reactive and not suitable for proactive hunting. Option B (Microsoft 365 Defender alerts) only surfaces known malicious apps, not all instances. Option C (CloudAppEvents table and AppGovernance) can be used, but the activity log is more direct and complete for hunting all installations, as CloudAppEvents may not capture every installation event or may require complex queries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Review Conditional Access app control policies for any block rules

    Why it's wrong here

    Conditional Access app control policies are session-level controls that define when access to a cloud app is allowed or blocked, but they do not detect or record OAuth app installation events. Their purpose is to enforce access conditions based on user, device, location, and risk, not to maintain an inventory of third-party apps that have been granted tenant permissions. Checking block rules would only reveal apps explicitly targeted by a policy, not the full set of installed app instances, so it cannot support a complete outbreak investigation.

  • ✗

    Check Microsoft 365 Defender alerts for malicious OAuth apps

    Why it's wrong here

    Microsoft 365 Defender alerts are generated by detection and response logic that classifies OAuth apps as malicious based on known indicators, such as suspicious publisher, unusual permissions, or anomalous activity. If the app under investigation has not been flagged by these detections, no alert will appear, and alerts do not provide a reliable enumeration of every app instance. An alert-centric approach overlooks dormant or unclassified installations and therefore cannot serve as the primary hunting method.

  • ✗

    Query the Microsoft 365 Defender advanced hunting table 'CloudAppEvents' for app installation events and then use 'AppGovernance' to list all apps

    Why it's wrong here

    The CloudAppEvents table in advanced hunting does contain events such as 'Install app' and is a valid source for locating installation activity. However, AppGovernance is not a table in the Microsoft 365 Defender advanced hunting schema; it is a dashboard feature within Microsoft Defender for Cloud Apps. Using it as a table name in a query would fail, and the correct subsequent step is to consult the Cloud App Security app catalog, which lists all third-party OAuth app instances. Thus the proposed approach conflates a feature with a queryable data source.

  • ✓

    Use the Cloud App Security activity log to search for 'Install app' events and then review the 'App governance' dashboard for all instances

    Why this is correct

    In Microsoft Defender for Cloud Apps, the activity log is the authoritative source for operational events, and filtering for the activity type 'Install app' directly surfaces when an OAuth app was introduced to the tenant. After identifying these installation events, the App governance dashboard provides a unified inventory of all app instances, including permissions, publisher, and usage, enabling the hunter to scope the outbreak. This sequence—find the installation event, then pivot to the governance inventory—matches the intended workflow for OAuth app threat hunting.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.