Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Defender for Cloud Apps. An alert indicates that a user is downloading large amounts of data from SharePoint Online. What should you do first to investigate?

⚠ Common exam trap

Many exam-takers confuse immediate governance actions (like suspending or blocking) with the proper investigative first step, failing to recognize that Defender for Cloud Apps requires log review to confirm the alert's validity before applying any automated or manual response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the user's activity log in Defender for Cloud Apps.

The first step in investigating a potential data exfiltration alert is to review the user's activity log in Defender for Cloud Apps. This log provides granular details about the specific files downloaded, the volume of data, the time frame, and the source IP address, allowing you to validate whether the activity is anomalous or legitimate before taking any restrictive action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Govern the user by suspending their account.

    Why it's wrong here

    Suspending the user account is a governance action meant to be taken after confirming malicious intent, not as a first response. In Defender for Cloud Apps, automated governance actions should be triggered by policies that already incorporate context; doing this manually without reviewing activity logs risks locking out a legitimate user and causing unnecessary business disruption. Investigate first, then apply targeted, reversible controls.

  • ✓

    Review the user's activity log in Defender for Cloud Apps.

    Why this is correct

    Reviewing the user's activity log in Defender for Cloud Apps is the foundational step for incident investigation. It provides forensic detail such as exact timestamps, source IP addresses, user agents, and the number of files downloaded, allowing you to compare this behavior against the user's baseline and organizational anomalies. This evidence is required to determine whether the downloads constitute a real exfiltration threat or are an outlier caused by a legitimate business task.

  • ✗

    Create a new IP address range for the organization.

    Why it's wrong here

    Creating a new IP address range is a configuration task that changes how Defender for Cloud Apps categorizes network locations, not an investigative step for a specific incident. While IP ranges are useful for aligning policies to trusted offices or known egress points, they have no effect on the immediate need to examine a user's existing activity. This action would alter future event processing but does nothing to clarify the current suspicious downloads.

  • ✗

    Block the SharePoint Online app for all users in Defender for Cloud Apps.

    Why it's wrong here

    Blocking the SharePoint Online app for all users is a blanket tenant-wide action that would halt all legitimate file collaboration and access across the organization. Defender for Cloud Apps supports granular controls such as user-specific policies, conditional access conditions, or session monitoring, allowing you to restrict a single user without disrupting the rest of the workforce. Such a disproportionate response would likely cause more operational damage than the suspicious downloads themselves and should only be considered after confirming a widespread threat.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.