Courseiva
Perform threat huntingeasyMultiple ChoiceObjective-mapped

SC-200 Perform threat hunting Practice Question

A threat hunter wants to proactively search for signs of ransomware activity in the environment using Microsoft Sentinel. Which data source is most likely to provide early indicators of ransomware, such as mass file renaming or encryption?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Endpoint advanced hunting tables like DeviceFileEvents and DeviceProcessEvents

(Microsoft Defender for Endpoint) provides advanced hunting on endpoint processes and file events, which can detect mass file modifications indicative of ransomware. Option A (Azure AD sign-in logs) logs authentication events. Option C (Azure Activity Log) logs control plane operations. Option D (Office 365 audit logs) logs cloud app activities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure AD sign-in logs

    Why it's wrong here

    Azure AD sign-in logs log authentication events, which are not early indicators of mass file renaming or encryption.

  • Microsoft Defender for Endpoint advanced hunting tables like DeviceFileEvents and DeviceProcessEvents

    Why this is correct

    Microsoft Defender for Endpoint advanced hunting tables like DeviceFileEvents and DeviceProcessEvents provide endpoint-level events that can detect mass file modifications indicative of ransomware.

  • Azure Activity Log

    Why it's wrong here

    Azure Activity Log logs control plane operations, not file-level changes on endpoints.

  • Office 365 audit logs (UnifiedAuditLog)

    Why it's wrong here

    Office 365 audit logs log cloud app activities, not endpoint file events.

About these practice questions

One of 1,235 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.