Courseiva

SC-200 Respond to security incidents Practice Question

An incident response playbook in Microsoft Sentinel has a step: 'Investigate the user's recent activities using Microsoft 365 Defender.' Which data source would provide the most relevant information for this step?

⚠ Common exam trap

It's easy for candidates to confuse Azure Activity Log (which logs Azure resource operations) with user activity logs in Microsoft 365, or assume that any Microsoft security tool (like Purview DLP) would contain the needed user activity data, when only the Microsoft 365 Defender user investigation page provides the specific, integrated view required by the playbook step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft 365 Defender's user investigation page

The Microsoft 365 Defender user investigation page is the correct data source because it provides a consolidated view of a user's activities across Microsoft 365 services, including email, Teams, and endpoint alerts. This directly supports the incident response step of investigating recent user activities within the Microsoft 365 Defender ecosystem, which is the explicit scope of the playbook step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Activity Log

    Why it's wrong here

    The Azure Activity Log is a subscription-level platform log that records control-plane events such as resource creation, deletion, and configuration changes, as well as RBAC operations. It does not capture user activities across Microsoft 365, such as email, Teams, or file access, because those occur in the data plane of Exchange, SharePoint, and other M365 workloads. An analyst investigating a compromised user would not find a unified user activity timeline in this log.

  • ✗

    Microsoft Purview Data Loss Prevention reports

    Why it's wrong here

    Microsoft Purview Data Loss Prevention reports focus exclusively on DLP policy matches, rule hits, and false positive/negative metrics for sensitive data in transit and at rest. They are aggregate operational reports rather than an entity-centric investigation experience, and they do not include general user activities like sign-in events, alert history, or device behaviors. For user-centric investigation, you need a tool that correlates a single user's signals across security domains, not a compliance report surface.

  • ✓

    Microsoft 365 Defender's user investigation page

    Why this is correct

    The Microsoft 365 Defender user investigation page (now within the unified Microsoft Defender XDR) provides a single, entity-centric view of a user's alerts, incidents, sign-ins, and related activities across identities, endpoints, email, and cloud apps. It automatically correlates evidence and provides a timeline that allows an incident responder to quickly detect the scope and blast radius of a compromised account. This is the correct investigation surface because it is specifically designed for user entity investigation, and Sentinel can ingest these detections through the Microsoft 365 Defender connector.

  • ✗

    Azure Resource Graph

    Why it's wrong here

    Azure Resource Graph is an Azure service designed for efficiently querying and exploring your Azure resource inventory at scale using KQL across subscriptions and management groups. It is intended for resource compliance, cost reporting, and change tracking, but it does not contain user activity logs, security alerts, or incident data. Attempting to use Resource Graph to investigate a user's activities would fail because it isn't indexed by user identity and merely reflects the current state of resources.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.