SC-200 Perform threat hunting Practice Question
Your organization uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. During a threat hunt, you find that a user accessed a sensitive SharePoint site from an anonymous IP address. Which hunting method would best identify all users who accessed the same site from similar anonymous IPs?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Query CloudAppEvents in Advanced hunting for the SharePoint site URL and filter by IP category 'AnonymousProxy'
Using KQL to query CloudAppEvents for the specific SharePoint site and filtering by IP address categories (e.g., AnonymousProxy) is the most direct method. Option D (Microsoft Entra ID sign-in logs) may not include SharePoint site-level access. Option B (Microsoft Defender for Endpoint) is for endpoint activities. Option C (Microsoft Purview) focuses on data classification and governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Query CloudAppEvents in Advanced hunting for the SharePoint site URL and filter by IP category 'AnonymousProxy'
Why this is correct
CloudAppEvents holds Microsoft Defender for Cloud Apps activity records, including SharePoint access and the IP category field. Filtering on the site URL and AnonymousProxy identifies every user who reached that site from anonymous IPs, which Sentinel's sign-in tables cannot surface.
- ✗
Query DeviceEvents for network connections from the anonymous IP
Why it's wrong here
DeviceEvents holds endpoint process and network telemetry, not cloud SharePoint access records, so it cannot identify users who accessed the site. It is tempting because it does contain network connection data, but SharePoint access is logged in Defender for Cloud Apps activity logs, not on the device.
- ✗
Use Microsoft Purview to scan for sensitive data accessed from anonymous IPs
Why it's wrong here
Microsoft Purview scans and classifies data content; it does not record which users accessed a site from which IP address, so it cannot answer the hunt. It is tempting because Purview covers sensitive data, but the required access-and-IP correlation sits in Defender for Cloud Apps activity logs.
- ✗
Search Microsoft Entra ID sign-in logs for the same IP
Why it's wrong here
Microsoft Entra ID sign-in logs record authentication events, not SharePoint file or site access, so they cannot enumerate users who accessed the same site from anonymous IPs. It is tempting because sign-in logs do surface IP addresses, but the required activity data lives in Defender for Cloud Apps or Sentinel, not the sign-in log.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.