Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

You are hunting for possible data exfiltration via email in Microsoft 365. Which data source in Microsoft Sentinel provides the most relevant telemetry for email forwarding rules?

⚠ Common exam trap

SC-200 often tests whether candidates confuse CASB-level anomaly detection (Defender for Cloud Apps) with the raw audit telemetry that actually records the malicious configuration change — the audit log is the source of truth, not the analytics layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Office 365 audit logs (Exchange)

Office 365 audit logs (Exchange) capture mailbox-level activity including the New-InboxRule, Set-InboxRule, and Set-Mailbox operations that create or modify forwarding rules (ForwardTo, RedirectTo, ForwardAsAttachmentTo). This is the authoritative telemetry source for detecting email-based exfiltration via auto-forwarding in Microsoft 365. Defender for Cloud Apps can surface anomalies but relies on the same underlying audit stream, making the native Office 365 audit log the most direct and complete source.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Cloud Apps logs

    Why it's wrong here

    Microsoft Defender for Cloud Apps logs aggregate activity from connected cloud apps, but they don't inspect the Exchange Online mailbox properties that govern forwarding and inbox rules. While the Office 365 connector can ingest some Exchange events, Defender for Cloud Apps' native schema focuses on user and app behavior, not granular mailbox rule mutations. To see a specific Set-Mailbox or New-InboxRule operation, you need the Exchange workload in the Unified Audit Log, not Defender for Cloud Apps' log pipeline.

  • ✗

    Windows Security Events

    Why it's wrong here

    Windows Security Event logs are generated by the operating system for authentication, process creation, and object access on endpoints and servers, and they have no awareness of cloud mailbox configurations. A malicious modification of a mailbox forwarding rule in Exchange Online never receives a corresponding Windows event ID, even if the user is Microsoft Entra ID joined, because the action occurs in Microsoft 365's service infrastructure. These logs only help you identify a host compromise, not the Exchange Online rule change that enables exfiltration.

  • ✗

    Microsoft Entra ID sign-in logs

    Why it's wrong here

    Microsoft Entra ID sign-in logs record successful and failed authentication attempts, including factors like IP, device, and conditional access, but they do not capture post-authentication activities such as mailbox rule modifications. An attacker who signs in and later adds a forwarding rule will appear in sign-in logs only as a normal login, with no indication that an email exfiltration rule was created. To detect asynchronous actions like forwarding changes, you must query the Exchange workload's audit events rather than the authentication telemetry.

  • ✓

    Office 365 audit logs (Exchange)

    Why this is correct

    Office 365 audit logs, specifically the Exchange workload, are the authoritative source because they capture changes to mailbox forwarding and inbox rules. Operations like Set-Mailbox, which includes modifications to ForwardingSmtpAddress, and New-InboxRule or Set-InboxRule with RedirectTo are logged with the actor's UPN, the exact timestamp, and the target mailbox. These events are accessible via the Microsoft Purview compliance portal or the Search-UnifiedAuditLog cmdlet, making them the definitive evidence for a data exfiltration via email investigation.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.