Courseiva

SC-200 Respond to security incidents Practice Question

You are a Security Operations Analyst investigating a potential insider threat. A user's account was flagged for downloading a large number of files from SharePoint Online. You need to review the user's activity and determine if the behavior is malicious. You have Microsoft Defender for Cloud Apps and Microsoft Sentinel configured. Which Microsoft Sentinel data source should you query to analyze the user's file download activities in SharePoint?

⚠ Common exam trap

The trap here is assuming that CloudAppEvents or AuditLogs contain SharePoint file download details, when in fact OfficeActivity is the dedicated table for Microsoft 365 audit events including SharePoint.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

OfficeActivity table

The OfficeActivity table is the correct data source for SharePoint Online file download activities. It captures detailed audit events such as FileDownloaded, including user, file name, and client IP, enabling you to assess the scale and nature of the downloads and determine if the behavior is suspicious.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AuditLogs table

    Why it's wrong here

    AuditLogs in Microsoft Sentinel typically refers to Microsoft Entra ID audit logs, which capture directory changes and administrative activities, not SharePoint file operations. SharePoint file downloads are recorded in OfficeActivity, not AuditLogs. Using AuditLogs would not provide the necessary file-level details for the investigation.

  • ✓

    OfficeActivity table

    Why this is correct

    The OfficeActivity table in Microsoft Sentinel contains audit logs from Microsoft 365, including SharePoint Online and OneDrive for Business. It records events such as FileDownloaded, FileAccessed, and FileUploaded, along with user and file details. Querying this table allows you to analyze the user's file download activities and assess the volume and sensitivity of the files involved.

  • ✗

    CloudAppEvents table

    Why it's wrong here

    CloudAppEvents contains activity logs from Microsoft Defender for Cloud Apps, which covers many cloud apps but may not include the granular SharePoint file download events unless specifically configured. While it can show user activities, the native OfficeActivity table provides more direct and detailed SharePoint audit data for file-level operations.

  • ✗

    SigninLogs table

    Why it's wrong here

    SigninLogs records Microsoft Entra ID sign-in events, including user, IP, and conditional access details. It does not contain file download activities from SharePoint. While sign-in data is useful for correlating access, it cannot show which files were downloaded or the volume of data transferred, so it is not the right source for this analysis.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.