SC-200 Perform threat hunting Practice Question
A threat hunter wants to proactively search for signs of ransomware activity in the environment using Microsoft Sentinel. Which data source is most likely to provide early indicators of ransomware, such as mass file renaming or encryption?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Endpoint advanced hunting tables like DeviceFileEvents and DeviceProcessEvents
(Microsoft Defender for Endpoint) provides advanced hunting on endpoint processes and file events, which can detect mass file modifications indicative of ransomware. Option A (Azure AD sign-in logs) logs authentication events. Option C (Azure Activity Log) logs control plane operations. Option D (Office 365 audit logs) logs cloud app activities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure AD sign-in logs
Why it's wrong here
Azure AD sign-in logs log authentication events, which are not early indicators of mass file renaming or encryption.
- ✓
Microsoft Defender for Endpoint advanced hunting tables like DeviceFileEvents and DeviceProcessEvents
Why this is correct
Microsoft Defender for Endpoint advanced hunting tables like DeviceFileEvents and DeviceProcessEvents provide endpoint-level events that can detect mass file modifications indicative of ransomware.
- ✗
Azure Activity Log
Why it's wrong here
Azure Activity Log logs control plane operations, not file-level changes on endpoints.
- ✗
Office 365 audit logs (UnifiedAuditLog)
Why it's wrong here
Office 365 audit logs log cloud app activities, not endpoint file events.
Go deeper
Related to this question
About these practice questions
One of 1,235 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.