SC-200 Perform threat hunting Practice Question
A threat hunter wants to use Microsoft Defender for Cloud Apps to hunt for suspicious OAuth app permissions. Which activity type should the analyst investigate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
OAuth app granting permissions
Suspicious OAuth app permissions are directly indicated by the activity type 'OAuth app granting permissions'. Option A (Failed logon attempts) is incorrect because it relates to authentication failures, not OAuth permissions. Option B (File download from SharePoint) is incorrect because it concerns data access, not permission grants. Option C (Mailbox forwarding rule created) is incorrect because it involves email rules, not OAuth authorizations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Failed logon attempts
Why it's wrong here
Failed logon attempts surface brute-force or credential-stuffing activity against identities, not OAuth consent grants or permission changes. Tempting because sign-in anomalies often indicate compromise, but hunting suspicious OAuth app permissions requires the Consent to application or Add OAuth app activity type instead.
- ✗
File download from SharePoint
Why it's wrong here
File downloads from SharePoint show data access or exfiltration behaviour, not OAuth permission grants. Tempting because mass downloads often signal compromised accounts, but the hunt targets suspicious OAuth app permissions, which surface as Consent to application or Add OAuth app activities in Defender for Cloud Apps.
- ✗
Mailbox forwarding rule created
Why it's wrong here
Mailbox forwarding rules indicate exfiltration setup after compromise, not OAuth permission grants. Tempting because forwarding rules are a classic post-compromise persistence mechanism worth hunting, yet suspicious OAuth app permissions appear under Consent to application or Add service principal activity types.
- ✓
OAuth app granting permissions
Why this is correct
OAuth app granting permissions directly records consent events, capturing the scopes granted to each application. This satisfies the hunter's requirement to identify suspicious OAuth permissions, as the activity log exposes the specific delegated or application permissions assigned, enabling detection of illicit access or over-privileged third-party apps.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.