mediumMultiple Choice
SC-200 Practice Question: During an incident investigation, an analyst…
During an incident investigation, an analyst notices a compromised user account that was used to access sensitive data from SharePoint Online. Which Microsoft 365 Defender workload would provide the most relevant alerts for suspicious file access patterns?
⚠ Common exam trap
Test-takers frequently confuse Microsoft Defender for Cloud Apps with Microsoft Defender for Office 365, assuming Office 365 covers all cloud workloads, but Cloud Apps is specifically designed for SaaS app security and anomaly detection in services like SharePoint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps (Option C) is the correct workload because it provides visibility into cloud application usage, including SharePoint Online, and can generate alerts for suspicious file access patterns such as mass download, unusual file sharing, or access from anomalous locations. It uses behavioral analytics and anomaly detection to identify compromised accounts accessing sensitive data in SaaS applications like SharePoint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Microsoft Defender for Endpoint is an endpoint detection and response solution that collects telemetry from onboarded devices—processes, file creations, network connections, and command-line activity. While it can indicate that a device reached SharePoint Online, it does not see the cloud-side file access events, sharing changes, or permission modifications, so it cannot alert specifically on suspicious file access patterns in a cloud app.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 protects email content and collaboration workloads against malicious payloads, phishing, and unsafe links via Safe Attachments and Safe Links for Exchange Online, SharePoint, and OneDrive. Its focus is on content-borne threats, not on who accessed a file, when, or from where; it lacks the cloud app session telemetry and user behavioral analytics needed to flag anomalous SharePoint file access patterns.
- ✓
Microsoft Defender for Cloud Apps
Why this is correct
Microsoft Defender for Cloud Apps functions as a cloud access security broker (CASB) with API connectors to SharePoint Online and other SaaS apps. It aggregates file access and sharing events, applies user and entity behavior analytics (UEBA) to detect impossible travel, mass downloads, and abnormal external sharing, and can generate the exact type of suspicious file access alert an analyst would investigate in this scenario.
- ✗
Microsoft Defender for Identity
Why it's wrong here
Microsoft Defender for Identity is an identity security product that parses on-premises Active Directory and network signals to detect techniques like pass-the-hash, user enumeration, and lateral movement. It focuses on authentication and account compromise across identity infrastructure, but it does not ingest cloud app file access logs or monitor data-plane operations in SharePoint, making it insufficient for detecting suspicious file access patterns.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.