SC-200 Unusual behavior alerts Practice Question
Which THREE actions are appropriate when investigating a potential data exfiltration incident in Microsoft Defender for Cloud Apps?
⚠ Common exam trap
Candidates may confuse containment actions (e.g., suspending the user) with investigative steps, or mistakenly think device inventory is relevant in cloud app investigations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the app dashboard to view unusual behavior alerts
Options B, D, and E are correct. Option B: Using the app dashboard to view unusual behavior alerts provides context about potential exfiltration. Option D: Checking file policy matches helps identify which files were flagged as suspicious. Option E: Reviewing the user's activity log in Defender for Cloud Apps helps determine the scope of the exfiltration. Option A is incorrect because checking device inventory is not a cloud app investigation action—it applies to endpoint devices. Option C is incorrect because suspending the user's account is a containment action, not an investigative step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check the device inventory for suspicious applications
Why it's wrong here
Device inventory in Microsoft Defender for Endpoint lists managed endpoints and installed applications, which is more relevant to traditional malware or device-based investigations. Suspicious applications on a device do not automatically explain activity in cloud apps because an exfiltration event in Defender for Cloud Apps is tied to user actions, file policies, and network sessions, not endpoint software. Checking device inventory here would be a distraction from the cloud app–centric investigation path.
- ✓
Use the app dashboard to view unusual behavior alerts
Why this is correct
The app dashboard in Defender for Cloud Apps surfaces anomaly detection alerts, such as impossible travel, mass download, or activity from a previously unseen IP. These alerts are produced by user and entity behavior analytics and serve as the initial signal that an exfiltration attempt may be in progress. Reviewing this dashboard is a valid investigative step because it helps you prioritize which users and files warrant deeper log analysis, rather than assuming any single event is malicious.
- ✗
Suspend the user's account immediately
Why it's wrong here
Suspending the user's account is a containment measure, not an investigative one, and performing it before gathering evidence can disrupt legitimate business operations and tip off a potential attacker. Investigation should first rely on read-only sources like alerts, file policy matches, and activity logs to confirm that malicious activity actually occurred. Only after you have enough evidence to classify the incident as a true positive should you move to remediation actions such as account suspension.
- ✓
Check the file policy matches for the user
Why this is correct
File policy matches in Defender for Cloud Apps identify files that violate DLP policies, such as those containing sensitive content that is shared externally or downloaded by a user. Each match provides specifics like the file name, owner, and the policy rule that was triggered, giving direct evidence of what data may have been exfiltrated. This step moves you from a vague alert to concrete artifacts, enabling you to assess the scope and sensitivity of the potential data loss.
- ✓
Review the user's activity log in Defender for Cloud Apps
Why this is correct
The activity log in Defender for Cloud Apps provides a chronological, filterable record of every user action across connected cloud apps, including file downloads, external shares, and permission changes. Reviewing this log for the affected user lets you reconstruct the sequence of events around the time of the suspicious alert, confirming whether exfiltration occurred and identifying additional affected files. This is a core investigative step because it provides the raw evidence needed to validate alerts and policy matches.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.