Courseiva
mediumMultiple Choice

SC-200 Uses Microsoft 365 Defender Practice Question

An organization uses Microsoft 365 Defender. A security analyst is investigating an incident where a user's device was compromised. The analyst wants to determine if the attacker attempted to access sensitive files stored in SharePoint Online from that device. Which advanced hunting table should the analyst query to find file access events from cloud apps?

⚠ Common exam trap

It's easy for candidates to confuse DeviceFileEvents (local file events) with cloud file access events, not realizing that SharePoint Online actions are logged only in CloudAppEvents, not in device-level tables.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudAppEvents

The CloudAppEvents table in Microsoft 365 Defender captures audit logs for cloud applications, including SharePoint Online. It records file access events such as viewing, downloading, or modifying files, making it the correct table to query when investigating attacker attempts to access sensitive files from a compromised device.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    CloudAppEvents

    Why this is correct

    CloudAppEvents is the correct table because it specifically records activities performed in Microsoft 365 cloud services, including SharePoint Online. This schema captures rich details about file operations such as downloads, uploads, modifications, and file access by users and apps. A security analyst querying for suspicious file access in SharePoint would filter this table by Application and ActionType fields to identify the exact activity.

  • ✗

    IdentityLogonEvents

    Why it's wrong here

    IdentityLogonEvents is incorrect because it logs authentication events, such as successful or failed user sign-ins to Microsoft Entra ID, rather than activities within cloud applications. While it may reveal the identity used to access a resource, it does not include file-level operations like opening or downloading a document from SharePoint. This table is useful for investigating sign-in anomalies, not cloud file access.

  • ✗

    DeviceFileEvents

    Why it's wrong here

    DeviceFileEvents is incorrect because it tracks file system events occurring on endpoints, such as file creation, modification, and deletion on local drives or attached media, collected by Microsoft Defender for Endpoint. These events originate from device-level sensors and do not include file access that transpires in a cloud service like SharePoint Online. Even if a file is synced via OneDrive, DeviceFileEvents records the local sync operation, not the cloud-side access that is the focus of this scenario.

  • ✗

    EmailEvents

    Why it's wrong here

    EmailEvents is incorrect because it captures email-related telemetry, including message processing events like delivery, send, and malicious content detections in Exchange Online. This table is focused on email traffic and attachments, not on file access in SharePoint or other cloud applications. A query for file access permissions would find no relevant data in EmailEvents because the table lacks fields for cloud storage file operations.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.