Courseiva
mediumMultiple Choice

SC-200 Practice Question: During an incident investigation, an analyst…

During an incident investigation, an analyst notices a compromised user account that was used to access sensitive data from SharePoint Online. Which Microsoft 365 Defender workload would provide the most relevant alerts for suspicious file access patterns?

⚠ Common exam trap

Test-takers frequently confuse Microsoft Defender for Cloud Apps with Microsoft Defender for Office 365, assuming Office 365 covers all cloud workloads, but Cloud Apps is specifically designed for SaaS app security and anomaly detection in services like SharePoint.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps (Option C) is the correct workload because it provides visibility into cloud application usage, including SharePoint Online, and can generate alerts for suspicious file access patterns such as mass download, unusual file sharing, or access from anomalous locations. It uses behavioral analytics and anomaly detection to identify compromised accounts accessing sensitive data in SaaS applications like SharePoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint is an endpoint detection and response solution that collects telemetry from onboarded devices—processes, file creations, network connections, and command-line activity. While it can indicate that a device reached SharePoint Online, it does not see the cloud-side file access events, sharing changes, or permission modifications, so it cannot alert specifically on suspicious file access patterns in a cloud app.

  • ✗

    Microsoft Defender for Office 365

    Why it's wrong here

    Microsoft Defender for Office 365 protects email content and collaboration workloads against malicious payloads, phishing, and unsafe links via Safe Attachments and Safe Links for Exchange Online, SharePoint, and OneDrive. Its focus is on content-borne threats, not on who accessed a file, when, or from where; it lacks the cloud app session telemetry and user behavioral analytics needed to flag anomalous SharePoint file access patterns.

  • ✓

    Microsoft Defender for Cloud Apps

    Why this is correct

    Microsoft Defender for Cloud Apps functions as a cloud access security broker (CASB) with API connectors to SharePoint Online and other SaaS apps. It aggregates file access and sharing events, applies user and entity behavior analytics (UEBA) to detect impossible travel, mass downloads, and abnormal external sharing, and can generate the exact type of suspicious file access alert an analyst would investigate in this scenario.

  • ✗

    Microsoft Defender for Identity

    Why it's wrong here

    Microsoft Defender for Identity is an identity security product that parses on-premises Active Directory and network signals to detect techniques like pass-the-hash, user enumeration, and lateral movement. It focuses on authentication and account compromise across identity infrastructure, but it does not ingest cloud app file access logs or monitor data-plane operations in SharePoint, making it insufficient for detecting suspicious file access patterns.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.