SC-200 Perform threat hunting Practice Question
You are using Microsoft Defender for Cloud Apps to hunt for suspicious OAuth app permissions. Which activity type should you look for to detect a potentially malicious app that was granted high privileges by a user?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Consent to application
'Consent to application' (Option A). This activity captures when a user grants OAuth permissions to an application, which is the key indicator of high-privilege app consent. Option B, 'Add service principal', relates to creating a service principal object in Microsoft Entra ID, not user consent. Option C, 'Update application', involves modifying an app's configuration, not consent. Option D, 'Add app role assignment grant', is about assigning an app role to a user or group, which is a separate permission grant that does not involve user consent directly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Consent to application
Why this is correct
Consent to application records the OAuth grant event, capturing the user, the application and the scopes requested. This directly satisfies the stem's requirement to detect a malicious app granted high privileges by a user, since the consent activity surfaces the permission grant itself rather than later API usage.
- ✗
Add service principal
Why it's wrong here
Adding a service principal registers an enterprise application instance in the tenant; it does not record a user granting that app delegated permissions. It is tempting because service principal creation often accompanies app onboarding, and it would be the correct activity when hunting for unauthorised enterprise applications being provisioned without user consent.
- ✗
Update application
Why it's wrong here
Updating an application changes its registration properties, not the consent grant that confers high privileges on a user's behalf. It is tempting because app management activities appear in the same audit log, and updating an app would be the relevant event when investigating a compromised registration rather than a malicious consent.
- ✗
Add app role assignment grant
Why it's wrong here
Granting an app role assignment assigns a user or group to an application role; it does not capture the OAuth consent that delegates high privileges to the app itself. It is tempting because role assignments also elevate access, and this activity would be correct when auditing which users hold privileged roles within an enterprise application.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A threat hunter wants to use Microsoft Defender for Cloud Apps to hunt for suspicious OAuth app permissions. Which activity type should the analyst investigate?
easy- A.Failed logon attempts
- B.File download from SharePoint
- C.Mailbox forwarding rule created
- ✓ D.OAuth app granting permissions
Why D: Suspicious OAuth app permissions are directly indicated by the activity type 'OAuth app granting permissions'. Option A (Failed logon attempts) is incorrect because it relates to authentication failures, not OAuth permissions. Option B (File download from SharePoint) is incorrect because it concerns data access, not permission grants. Option C (Mailbox forwarding rule created) is incorrect because it involves email rules, not OAuth authorizations.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.