SC-200 Respond to security incidents Practice Question
During an incident investigation, you discover that an attacker used a legitimate account to access sensitive data in Microsoft Purview Information Protection. You need to identify what data was accessed and by whom. Which log source should you query?
⚠ Common exam trap
Many exam-takers confuse the unified audit log (option D) with Purview data access logs, not realizing that while the unified audit log captures many activities, Purview data access logs are the only source that specifically records label-based access events for sensitive data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview data access logs
Microsoft Purview data access logs (option B) are the correct source because they specifically record when users access sensitive data labeled with Microsoft Purview Information Protection, including details about what data was accessed and by whom. Unlike other logs, these capture data-level access events such as viewing, downloading, or modifying protected documents, which is essential for investigating an attacker using a legitimate account to exfiltrate sensitive information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft 365 Defender alerts
Why it's wrong here
Microsoft 365 Defender alerts are detection outputs generated by signals such as endpoint protection, email filtering, and identity analytics. Unlike raw access logs, they do not provide a continuous, item-level record of every user action on sensitive data, nor do they reveal the exact documents or resources that were accessed during a campaign. Alerts only surface suspicious activity that triggered a rule or analytic, so they cannot serve as a complete forensic data-access trail.
- ✓
Microsoft Purview data access logs
Why this is correct
Microsoft Purview data access logs are the authoritative source for item-level access events in Office 365, recording details such as the specific document downloaded, the user identity, the timestamp, and the device or client IP. These logs are generated by Purview's content discovery and classification pipeline and capture both interactive and background access by apps or users. For an attacker exfiltrating sensitive files, these logs provide the precise chain of access needed to confirm what data was compromised, so this is the correct choice for the investigation.
- ✗
Microsoft Entra ID sign-in logs
Why it's wrong here
Microsoft Entra ID sign-in logs document authentication events, showing that a given user, service principal, or device successfully signed in, including the source IP, application, and conditional-access conditions. They do not, however, describe what happened after authentication—no record of which files were read, copied, or modified. An attacker who stole a session token could appear as a normal sign-in, while the actual data access would remain invisible in Entra ID, making these logs insufficient to answer 'what data was accessed?'
- ✗
Office 365 audit logs (unified audit log)
Why it's wrong here
The Office 365 unified audit log captures a broad set of administrator and user activities, such as mailbox operations, eDiscovery searches, and admin role changes, and can be queried via the Microsoft 365 Security & Compliance Center. However, not every Purview data access event is automatically routed to the unified audit log; sensitive-label access and content-exploitation events that Purview tracks may require enabling specific audit logging or integrating with other Purview solutions. Relying solely on the unified audit log risks missing the granular file-access events that are central to this incident, so it is less suitable than the dedicated Purview data access log.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.