Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender XDR and Microsoft Sentinel. You need to create a custom detection rule that triggers when a user is added to a privileged role in Microsoft Entra ID and within 5 minutes performs a mass download from SharePoint. Which approach should you use?

⚠ Common exam trap

Watch out — candidates often assume Microsoft 365 Defender (now Defender XDR) can correlate all Microsoft 365 data, but its custom detection rules are restricted to Defender XDR tables, not Entra ID or SharePoint audit logs, which are only available in Sentinel via dedicated connectors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a scheduled query rule in Microsoft Sentinel

The detection requires correlating events across Microsoft Entra ID (privileged role assignment) and SharePoint (mass download) within a 5-minute window. Microsoft Sentinel's scheduled query rules can ingest data from multiple sources (e.g., AuditLogs for Entra ID and SharePoint via Office 365 connector) and use KQL to join these events with a time constraint, making it the only native solution for cross-domain, time-bound custom detections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an advanced hunting query in Microsoft Defender XDR

    Why it's wrong here

    Advanced hunting in Microsoft Defender XDR is an investigation tool, not a detection engine; it runs KQL over the Defender XDR schema such as Device*, Email*, Identity* and CloudAppEvents, but it does not include Microsoft Purview audit logs such as SharePoint file events. A one-time query executed in the portal cannot continuously join Defender signals with Purview activity and generate alerts, so it cannot provide the multi-source correlation this scenario requires.

  • ✗

    Use a custom detection rule in Microsoft 365 Defender

    Why it's wrong here

    Custom detection rules in Microsoft 365 Defender are built on advanced hunting queries, so they inherit exactly the same data limitations: they can only run against tables already normalized in the Defender XDR schema, like AlertEvidence or DeviceLogonEvents. Because Microsoft Purview audit logs, including SharePoint user actions, are not present in that schema, a custom detection rule cannot join Defender alerts with those logs to perform the required correlation across Microsoft 365 and Defender signals.

  • ✗

    Use a Microsoft Purview insider risk policy

    Why it's wrong here

    Microsoft Purview Insider Risk Management is a policy-driven user behavior analytics solution focused on identifying potential data exfiltration and policy violations using predefined indicators from Microsoft 365 workloads such as SharePoint, OneDrive, Exchange, and DLP events. It does not ingest Microsoft Defender XDR security signals, nor does it support custom KQL queries or scheduled time-window joins, so it cannot perform the real-time correlation of Defender alerts and Microsoft 365 activity that the scenario demands.

  • ✓

    Create a scheduled query rule in Microsoft Sentinel

    Why this is correct

    A Microsoft Sentinel scheduled query rule is correct because Sentinel is a cloud-native SIEM that can ingest logs from both Microsoft Defender XDR (via the Defender XDR connector) and Microsoft 365/Purview (via the Office 365 and Microsoft 365 connectors). Using KQL, you can join these multiple tables on a common field like user principal name within a defined time window; the rule then runs on a schedule, applies detection logic, and raises an alert that can trigger incident creation and SOAR playbooks, enabling cross-workload correlation that Defender and Purview tools alone cannot provide.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.