SC-200 Perform threat hunting Practice Question
You are threat hunting in Microsoft Defender for Cloud Apps. You want to identify users who have enabled mailbox forwarding rules to external domains, which could indicate data exfiltration. Which log source should you query?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Office 365 audit logs
Microsoft Defender for Cloud Apps can ingest Office 365 audit logs, which include Exchange mailbox audit events for forwarding rules. Options B, C, and D are incorrect: Microsoft Entra ID sign-in logs (B) do not contain mailbox forwarding events, Windows Event logs from domain controllers (C) are device-focused and do not include Exchange mailbox rules, and Azure Network Watcher logs (D) are for network monitoring and do not include mailbox rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Office 365 audit logs
Why this is correct
Office 365 audit logs capture Exchange mailbox rule creation and modification events, including Set-InboxRule operations that forward mail externally. Querying this source in Microsoft Sentinel surfaces users who configured external forwarding, matching the exfiltration hunt.
- ✗
Microsoft Entra ID sign-in logs
Why it's wrong here
Sign-in logs record authentication events and conditional access outcomes, not Exchange mailbox rule creation. Forwarding rules to external domains appear in the unified audit log via Exchange mailbox auditing. Sign-in logs would be the right source for detecting anomalous or risky authentication, such as impossible travel or leaked credentials.
- ✗
Windows Event logs from domain controllers
Why it's wrong here
Domain controller event logs capture authentication, Kerberos and directory service activity, not Exchange Online mailbox configuration. Forwarding rules set through Outlook on the web or Exchange PowerShell are recorded in the Microsoft 365 unified audit log. Domain controller logs suit on-premises Active Directory compromise investigations.
- ✗
Azure Network Watcher logs
Why it's wrong here
Network Watcher logs capture IP flow and packet-level data, containing no mailbox rule or forwarding configuration. It tempts analysts correlating network anomalies with exfiltration, but detecting forwarding rules requires querying the Office 365 audit log, which records mailbox rule creation and modification events.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.