Courseiva

SC-200 Respond to security incidents Practice Question

During an incident investigation, you discover that an attacker used a legitimate account to access sensitive data in Microsoft Purview Information Protection. You need to identify what data was accessed and by whom. Which log source should you query?

⚠ Common exam trap

Many exam-takers confuse the unified audit log (option D) with Purview data access logs, not realizing that while the unified audit log captures many activities, Purview data access logs are the only source that specifically records label-based access events for sensitive data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview data access logs

Microsoft Purview data access logs (option B) are the correct source because they specifically record when users access sensitive data labeled with Microsoft Purview Information Protection, including details about what data was accessed and by whom. Unlike other logs, these capture data-level access events such as viewing, downloading, or modifying protected documents, which is essential for investigating an attacker using a legitimate account to exfiltrate sensitive information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft 365 Defender alerts

    Why it's wrong here

    Microsoft 365 Defender alerts are detection outputs generated by signals such as endpoint protection, email filtering, and identity analytics. Unlike raw access logs, they do not provide a continuous, item-level record of every user action on sensitive data, nor do they reveal the exact documents or resources that were accessed during a campaign. Alerts only surface suspicious activity that triggered a rule or analytic, so they cannot serve as a complete forensic data-access trail.

  • ✓

    Microsoft Purview data access logs

    Why this is correct

    Microsoft Purview data access logs are the authoritative source for item-level access events in Office 365, recording details such as the specific document downloaded, the user identity, the timestamp, and the device or client IP. These logs are generated by Purview's content discovery and classification pipeline and capture both interactive and background access by apps or users. For an attacker exfiltrating sensitive files, these logs provide the precise chain of access needed to confirm what data was compromised, so this is the correct choice for the investigation.

  • ✗

    Microsoft Entra ID sign-in logs

    Why it's wrong here

    Microsoft Entra ID sign-in logs document authentication events, showing that a given user, service principal, or device successfully signed in, including the source IP, application, and conditional-access conditions. They do not, however, describe what happened after authentication—no record of which files were read, copied, or modified. An attacker who stole a session token could appear as a normal sign-in, while the actual data access would remain invisible in Entra ID, making these logs insufficient to answer 'what data was accessed?'

  • ✗

    Office 365 audit logs (unified audit log)

    Why it's wrong here

    The Office 365 unified audit log captures a broad set of administrator and user activities, such as mailbox operations, eDiscovery searches, and admin role changes, and can be queried via the Microsoft 365 Security & Compliance Center. However, not every Purview data access event is automatically routed to the unified audit log; sensitive-label access and content-exploitation events that Purview tracks may require enabling specific audit logging or integrating with other Purview solutions. Relying solely on the unified audit log risks missing the granular file-access events that are central to this incident, so it is less suitable than the dedicated Purview data access log.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.