Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

Your organization uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. During a threat hunt, you find that a user accessed a sensitive SharePoint site from an anonymous IP address. Which hunting method would best identify all users who accessed the same site from similar anonymous IPs?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Query CloudAppEvents in Advanced hunting for the SharePoint site URL and filter by IP category 'AnonymousProxy'

Using KQL to query CloudAppEvents for the specific SharePoint site and filtering by IP address categories (e.g., AnonymousProxy) is the most direct method. Option D (Microsoft Entra ID sign-in logs) may not include SharePoint site-level access. Option B (Microsoft Defender for Endpoint) is for endpoint activities. Option C (Microsoft Purview) focuses on data classification and governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Query CloudAppEvents in Advanced hunting for the SharePoint site URL and filter by IP category 'AnonymousProxy'

    Why this is correct

    CloudAppEvents holds Microsoft Defender for Cloud Apps activity records, including SharePoint access and the IP category field. Filtering on the site URL and AnonymousProxy identifies every user who reached that site from anonymous IPs, which Sentinel's sign-in tables cannot surface.

  • ✗

    Query DeviceEvents for network connections from the anonymous IP

    Why it's wrong here

    DeviceEvents holds endpoint process and network telemetry, not cloud SharePoint access records, so it cannot identify users who accessed the site. It is tempting because it does contain network connection data, but SharePoint access is logged in Defender for Cloud Apps activity logs, not on the device.

  • ✗

    Use Microsoft Purview to scan for sensitive data accessed from anonymous IPs

    Why it's wrong here

    Microsoft Purview scans and classifies data content; it does not record which users accessed a site from which IP address, so it cannot answer the hunt. It is tempting because Purview covers sensitive data, but the required access-and-IP correlation sits in Defender for Cloud Apps activity logs.

  • ✗

    Search Microsoft Entra ID sign-in logs for the same IP

    Why it's wrong here

    Microsoft Entra ID sign-in logs record authentication events, not SharePoint file or site access, so they cannot enumerate users who accessed the same site from anonymous IPs. It is tempting because sign-in logs do surface IP addresses, but the required activity data lives in Defender for Cloud Apps or Sentinel, not the sign-in log.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.