mediumMultiple Choice
SC-200 Uses Microsoft 365 Defender Practice Question
An organization uses Microsoft 365 Defender. A security analyst is investigating an incident where a user's device was compromised. The analyst wants to determine if the attacker attempted to access sensitive files stored in SharePoint Online from that device. Which advanced hunting table should the analyst query to find file access events from cloud apps?
⚠ Common exam trap
It's easy for candidates to confuse DeviceFileEvents (local file events) with cloud file access events, not realizing that SharePoint Online actions are logged only in CloudAppEvents, not in device-level tables.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CloudAppEvents
The CloudAppEvents table in Microsoft 365 Defender captures audit logs for cloud applications, including SharePoint Online. It records file access events such as viewing, downloading, or modifying files, making it the correct table to query when investigating attacker attempts to access sensitive files from a compromised device.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
CloudAppEvents
Why this is correct
CloudAppEvents is the correct table because it specifically records activities performed in Microsoft 365 cloud services, including SharePoint Online. This schema captures rich details about file operations such as downloads, uploads, modifications, and file access by users and apps. A security analyst querying for suspicious file access in SharePoint would filter this table by Application and ActionType fields to identify the exact activity.
- ✗
IdentityLogonEvents
Why it's wrong here
IdentityLogonEvents is incorrect because it logs authentication events, such as successful or failed user sign-ins to Microsoft Entra ID, rather than activities within cloud applications. While it may reveal the identity used to access a resource, it does not include file-level operations like opening or downloading a document from SharePoint. This table is useful for investigating sign-in anomalies, not cloud file access.
- ✗
DeviceFileEvents
Why it's wrong here
DeviceFileEvents is incorrect because it tracks file system events occurring on endpoints, such as file creation, modification, and deletion on local drives or attached media, collected by Microsoft Defender for Endpoint. These events originate from device-level sensors and do not include file access that transpires in a cloud service like SharePoint Online. Even if a file is synced via OneDrive, DeviceFileEvents records the local sync operation, not the cloud-side access that is the focus of this scenario.
- ✗
EmailEvents
Why it's wrong here
EmailEvents is incorrect because it captures email-related telemetry, including message processing events like delivery, send, and malicious content detections in Exchange Online. This table is focused on email traffic and attachments, not on file access in SharePoint or other cloud applications. A query for file access permissions would find no relevant data in EmailEvents because the table lacks fields for cloud storage file operations.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.