Courseiva
mediumMultiple ChoiceObjective-mapped

SC-200 Practice Question: An analyst is investigating an incident where a…

An analyst is investigating an incident where a user's mailbox was compromised. The analyst wants to find all mailbox access events (e.g., logins, message access) performed from a specific IP address. Which Advanced Hunting table in Microsoft 365 Defender should be queried?

⚠ Common exam trap

Many candidates confuse Azure AD sign-in logs (AADSignInEventsBeta) with mailbox access logs, but Azure AD logs only capture authentication events, not the subsequent application-level operations within Exchange Online.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

CloudAppEvents

The CloudAppEvents table in Microsoft 365 Defender captures audit logs for cloud applications, including Exchange Online mailbox operations such as logins, message access, and folder bindings. This table contains the 'IPAddress' field, allowing the analyst to filter events from a specific IP address. Other tables lack the necessary scope of mailbox access events or the IP address field for this query.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • CloudAppEvents

    Why this is correct

    Correct. This table logs actions in cloud apps including mailbox access events.

  • EmailEvents

    Why it's wrong here

    EmailEvents contains information about email delivery, not mailbox access.

  • EmailAttachmentInfo

    Why it's wrong here

    This table stores information about email attachments, not access logs.

  • AADSignInEventsBeta

    Why it's wrong here

    AADSignInEvents tracks user sign-ins to Microsoft Entra ID, not granular mailbox operations.

About these practice questions

Courseiva writes every SC-200 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.