SC-200 Perform threat hunting Practice Question
You are a security operations analyst for Contoso Ltd. The company uses Microsoft Sentinel as its SIEM and Microsoft Defender for Cloud Apps for SaaS security. You are tasked with threat hunting for potential data exfiltration via Microsoft SharePoint Online. You need to create a hunting query that identifies users who have downloaded an unusually high number of files from SharePoint within a short time window compared to their historical baseline. The query should be run in Microsoft Sentinel using the OfficeActivity table. Which of the following approaches should you take?
⚠ Common exam trap
SC-200 often tests the correct table for a given data source; candidates may mistakenly choose CommonSecurityLog or SecurityAlert instead of OfficeActivity for SharePoint activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Query the OfficeActivity table, filter for Operation=='FileDownloaded', summarize by UserId and bin(TimeGenerated, 1h), then use a join with a historical baseline table to detect deviations
The OfficeActivity table in Microsoft Sentinel contains audit logs for Microsoft 365 services, including SharePoint Online. Filtering for Operation=='FileDownloaded' and summarizing by UserId and time bin allows you to count downloads per user per hour. Joining with a historical baseline table (e.g., created via a separate query or using the 'summarize' operator over a longer period) enables detection of anomalies compared to each user's normal behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the HuntingBookmark table to search for user activity
Why it's wrong here
HuntingBookmark stores saved query results and analyst notes, not raw activity, so it cannot establish a per-user download baseline. It tempts because bookmarks are central to Sentinel hunting workflows, and it would be correct when persisting or annotating findings from a completed query rather than querying OfficeActivity for the underlying events.
- ✗
Query the CommonSecurityLog table for SharePoint events and look for high volumes of outbound traffic
Why it's wrong here
CommonSecurityLog holds CEF events from third-party security appliances, not SharePoint audit records, so it cannot expose per-user file download counts. It tempts because network egress volume can suggest exfiltration, and it would be correct if the source were a firewall or proxy logging outbound traffic rather than Microsoft 365 audit data.
- ✓
Query the OfficeActivity table, filter for Operation=='FileDownloaded', summarize by UserId and bin(TimeGenerated, 1h), then use a join with a historical baseline table to detect deviations
Why this is correct
Filtering OfficeActivity for Operation=='FileDownloaded' and summarising with bin(TimeGenerated, 1h) aggregates download counts per user per hour, satisfying the short-window requirement. Joining against a historical baseline table then surfaces deviations from each user's normal behaviour, which is precisely the anomaly detection the stem demands for SharePoint exfiltration hunting.
- ✗
Query the SecurityAlert table for alerts related to data exfiltration
Why it's wrong here
SecurityAlert contains generated alerts, not raw SharePoint operations, so it cannot compute download counts against a historical baseline. It tempts because data exfiltration alerts sound directly relevant, and it would be correct if the task were triaging existing detections rather than proactively hunting unalerted anomalous behaviour in OfficeActivity.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.