Courseiva
Perform threat hunting →hardMultiple Choice

SC-200 Perform threat hunting Practice Question

You are a security operations analyst for Contoso Ltd. The company uses Microsoft Sentinel as its SIEM and Microsoft Defender for Cloud Apps for SaaS security. You are tasked with threat hunting for potential data exfiltration via Microsoft SharePoint Online. You need to create a hunting query that identifies users who have downloaded an unusually high number of files from SharePoint within a short time window compared to their historical baseline. The query should be run in Microsoft Sentinel using the OfficeActivity table. Which of the following approaches should you take?

⚠ Common exam trap

SC-200 often tests the correct table for a given data source; candidates may mistakenly choose CommonSecurityLog or SecurityAlert instead of OfficeActivity for SharePoint activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Query the OfficeActivity table, filter for Operation=='FileDownloaded', summarize by UserId and bin(TimeGenerated, 1h), then use a join with a historical baseline table to detect deviations

The OfficeActivity table in Microsoft Sentinel contains audit logs for Microsoft 365 services, including SharePoint Online. Filtering for Operation=='FileDownloaded' and summarizing by UserId and time bin allows you to count downloads per user per hour. Joining with a historical baseline table (e.g., created via a separate query or using the 'summarize' operator over a longer period) enables detection of anomalies compared to each user's normal behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the HuntingBookmark table to search for user activity

    Why it's wrong here

    HuntingBookmark stores saved query results and analyst notes, not raw activity, so it cannot establish a per-user download baseline. It tempts because bookmarks are central to Sentinel hunting workflows, and it would be correct when persisting or annotating findings from a completed query rather than querying OfficeActivity for the underlying events.

  • ✗

    Query the CommonSecurityLog table for SharePoint events and look for high volumes of outbound traffic

    Why it's wrong here

    CommonSecurityLog holds CEF events from third-party security appliances, not SharePoint audit records, so it cannot expose per-user file download counts. It tempts because network egress volume can suggest exfiltration, and it would be correct if the source were a firewall or proxy logging outbound traffic rather than Microsoft 365 audit data.

  • ✓

    Query the OfficeActivity table, filter for Operation=='FileDownloaded', summarize by UserId and bin(TimeGenerated, 1h), then use a join with a historical baseline table to detect deviations

    Why this is correct

    Filtering OfficeActivity for Operation=='FileDownloaded' and summarising with bin(TimeGenerated, 1h) aggregates download counts per user per hour, satisfying the short-window requirement. Joining against a historical baseline table then surfaces deviations from each user's normal behaviour, which is precisely the anomaly detection the stem demands for SharePoint exfiltration hunting.

  • ✗

    Query the SecurityAlert table for alerts related to data exfiltration

    Why it's wrong here

    SecurityAlert contains generated alerts, not raw SharePoint operations, so it cannot compute download counts against a historical baseline. It tempts because data exfiltration alerts sound directly relevant, and it would be correct if the task were triaging existing detections rather than proactively hunting unalerted anomalous behaviour in OfficeActivity.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.