SC-200 Perform threat hunting Practice Question
You are hunting for possible data exfiltration via email in Microsoft 365. Which data source in Microsoft Sentinel provides the most relevant telemetry for email forwarding rules?
⚠ Common exam trap
SC-200 often tests whether candidates confuse CASB-level anomaly detection (Defender for Cloud Apps) with the raw audit telemetry that actually records the malicious configuration change — the audit log is the source of truth, not the analytics layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Office 365 audit logs (Exchange)
Office 365 audit logs (Exchange) capture mailbox-level activity including the New-InboxRule, Set-InboxRule, and Set-Mailbox operations that create or modify forwarding rules (ForwardTo, RedirectTo, ForwardAsAttachmentTo). This is the authoritative telemetry source for detecting email-based exfiltration via auto-forwarding in Microsoft 365. Defender for Cloud Apps can surface anomalies but relies on the same underlying audit stream, making the native Office 365 audit log the most direct and complete source.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud Apps logs
Why it's wrong here
Microsoft Defender for Cloud Apps logs aggregate activity from connected cloud apps, but they don't inspect the Exchange Online mailbox properties that govern forwarding and inbox rules. While the Office 365 connector can ingest some Exchange events, Defender for Cloud Apps' native schema focuses on user and app behavior, not granular mailbox rule mutations. To see a specific Set-Mailbox or New-InboxRule operation, you need the Exchange workload in the Unified Audit Log, not Defender for Cloud Apps' log pipeline.
- ✗
Windows Security Events
Why it's wrong here
Windows Security Event logs are generated by the operating system for authentication, process creation, and object access on endpoints and servers, and they have no awareness of cloud mailbox configurations. A malicious modification of a mailbox forwarding rule in Exchange Online never receives a corresponding Windows event ID, even if the user is Microsoft Entra ID joined, because the action occurs in Microsoft 365's service infrastructure. These logs only help you identify a host compromise, not the Exchange Online rule change that enables exfiltration.
- ✗
Microsoft Entra ID sign-in logs
Why it's wrong here
Microsoft Entra ID sign-in logs record successful and failed authentication attempts, including factors like IP, device, and conditional access, but they do not capture post-authentication activities such as mailbox rule modifications. An attacker who signs in and later adds a forwarding rule will appear in sign-in logs only as a normal login, with no indication that an email exfiltration rule was created. To detect asynchronous actions like forwarding changes, you must query the Exchange workload's audit events rather than the authentication telemetry.
- ✓
Office 365 audit logs (Exchange)
Why this is correct
Office 365 audit logs, specifically the Exchange workload, are the authoritative source because they capture changes to mailbox forwarding and inbox rules. Operations like Set-Mailbox, which includes modifications to ForwardingSmtpAddress, and New-InboxRule or Set-InboxRule with RedirectTo are logged with the actor's UPN, the exact timestamp, and the target mailbox. These events are accessible via the Microsoft Purview compliance portal or the Search-UnifiedAuditLog cmdlet, making them the definitive evidence for a data exfiltration via email investigation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.