Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

During a threat hunt, you identify a user account that has been logging in from multiple geographic regions within a short time. Which Microsoft Defender for Cloud Apps feature should you use to investigate this anomaly?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Activity log

The Activity log in Microsoft Defender for Cloud Apps provides detailed records of user activities, including login locations and times, making it ideal for investigating anomalies like logins from multiple geographic regions. Option A (Cloud Discovery) is used to identify shadow IT and cloud app usage, not user login anomalies. Option B (App permissions) focuses on permissions granted to OAuth apps, not user activity. Option C (File policy) is for monitoring and protecting files, not login events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud Discovery

    Why it's wrong here

    Cloud Discovery analyses traffic logs to catalogue shadow IT and app usage, not identity sign-in geography, so it cannot correlate a user's concurrent sessions. It is tempting because it investigates cloud activity, and would be correct when identifying unsanctioned SaaS apps from firewall or proxy log uploads.

  • ✗

    App permissions

    Why it's wrong here

    App permissions reviews OAuth scopes granted to third-party applications, not the geographic origin of user authentications, so it cannot detect impossible travel. It is tempting because it examines risky cloud app access, and would be correct when auditing over-privileged or malicious OAuth consent grants.

  • ✗

    File policy

    Why it's wrong here

    File policy governs data-at-rest classification and DLP actions on stored content, not sign-in telemetry, so it cannot surface impossible-travel logins. It is tempting because it addresses cloud app data governance, and would be correct when blocking or auditing sensitive file uploads and shares in a monitored service.

  • ✓

    Activity log

    Why this is correct

    The activity log records every user action and sign-in event with source IP, location and timestamp, letting analysts correlate the impossible-travel sign-ins and trace subsequent suspicious activity. It directly satisfies the requirement to investigate an account authenticating from multiple geographic regions within a short window.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.