Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

A threat hunter wants to use Microsoft Defender for Cloud Apps to hunt for suspicious OAuth app permissions. Which activity type should the analyst investigate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

OAuth app granting permissions

Suspicious OAuth app permissions are directly indicated by the activity type 'OAuth app granting permissions'. Option A (Failed logon attempts) is incorrect because it relates to authentication failures, not OAuth permissions. Option B (File download from SharePoint) is incorrect because it concerns data access, not permission grants. Option C (Mailbox forwarding rule created) is incorrect because it involves email rules, not OAuth authorizations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Failed logon attempts

    Why it's wrong here

    Failed logon attempts surface brute-force or credential-stuffing activity against identities, not OAuth consent grants or permission changes. Tempting because sign-in anomalies often indicate compromise, but hunting suspicious OAuth app permissions requires the Consent to application or Add OAuth app activity type instead.

  • ✗

    File download from SharePoint

    Why it's wrong here

    File downloads from SharePoint show data access or exfiltration behaviour, not OAuth permission grants. Tempting because mass downloads often signal compromised accounts, but the hunt targets suspicious OAuth app permissions, which surface as Consent to application or Add OAuth app activities in Defender for Cloud Apps.

  • ✗

    Mailbox forwarding rule created

    Why it's wrong here

    Mailbox forwarding rules indicate exfiltration setup after compromise, not OAuth permission grants. Tempting because forwarding rules are a classic post-compromise persistence mechanism worth hunting, yet suspicious OAuth app permissions appear under Consent to application or Add service principal activity types.

  • ✓

    OAuth app granting permissions

    Why this is correct

    OAuth app granting permissions directly records consent events, capturing the scopes granted to each application. This satisfies the hunter's requirement to identify suspicious OAuth permissions, as the activity log exposes the specific delegated or application permissions assigned, enabling detection of illicit access or over-privileged third-party apps.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.