SC-200 Perform threat hunting Practice Question
During a threat hunt, you identify a user account that has been logging in from multiple geographic regions within a short time. Which Microsoft Defender for Cloud Apps feature should you use to investigate this anomaly?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Activity log
The Activity log in Microsoft Defender for Cloud Apps provides detailed records of user activities, including login locations and times, making it ideal for investigating anomalies like logins from multiple geographic regions. Option A (Cloud Discovery) is used to identify shadow IT and cloud app usage, not user login anomalies. Option B (App permissions) focuses on permissions granted to OAuth apps, not user activity. Option C (File policy) is for monitoring and protecting files, not login events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Discovery
Why it's wrong here
Cloud Discovery analyses traffic logs to catalogue shadow IT and app usage, not identity sign-in geography, so it cannot correlate a user's concurrent sessions. It is tempting because it investigates cloud activity, and would be correct when identifying unsanctioned SaaS apps from firewall or proxy log uploads.
- ✗
App permissions
Why it's wrong here
App permissions reviews OAuth scopes granted to third-party applications, not the geographic origin of user authentications, so it cannot detect impossible travel. It is tempting because it examines risky cloud app access, and would be correct when auditing over-privileged or malicious OAuth consent grants.
- ✗
File policy
Why it's wrong here
File policy governs data-at-rest classification and DLP actions on stored content, not sign-in telemetry, so it cannot surface impossible-travel logins. It is tempting because it addresses cloud app data governance, and would be correct when blocking or auditing sensitive file uploads and shares in a monitored service.
- ✓
Activity log
Why this is correct
The activity log records every user action and sign-in event with source IP, location and timestamp, letting analysts correlate the impossible-travel sign-ins and trace subsequent suspicious activity. It directly satisfies the requirement to investigate an account authenticating from multiple geographic regions within a short window.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.