Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

Your team is conducting a threat hunt for data exfiltration using Microsoft Defender for Cloud Apps. Which activity is most suspicious and should be included in the hunting query?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A user downloading hundreds of files from SharePoint Online in a short time.

Mass download of hundreds of files from SharePoint Online in a short time is a classic indicator of data exfiltration. Option D is correct. Option A is incorrect because viewing files is normal user activity and not indicative of exfiltration. Option B is incorrect because downloading a single file is routine and not suspicious. Option C is incorrect because sharing a file with an internal colleague is typical collaboration and less likely to be exfiltration than mass downloads or external sharing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A user viewing files in OneDrive for Business.

    Why it's wrong here

    Viewing files in OneDrive is read-only access by the data owner, producing no transfer of data outside the tenant. It tempts because OneDrive activity appears in Defender for Cloud Apps logs, but viewing lacks the volume, destination and exfiltration indicators that distinguish suspicious activity from normal access.

  • ✗

    A user downloading a single file from SharePoint Online.

    Why it's wrong here

    A single SharePoint download is routine user behaviour, so it generates no exfiltration signal; bulk downloads or downloads to unmanaged devices are the suspicious patterns. It tempts because SharePoint holds sensitive data and downloads can precede exfiltration, but one file lacks the volume or anomaly that Defender for Cloud Apps hunting queries target.

  • ✗

    A user sharing a file with an internal colleague.

    Why it's wrong here

    Internal sharing stays within the tenant boundary, so no data leaves the organisation and no exfiltration alert fires. It tempts because file-sharing activity is logged and auditable, but external or anonymous sharing links are the suspicious events; internal collaboration is expected and would not warrant hunting.

  • ✓

    A user downloading hundreds of files from SharePoint Online in a short time.

    Why this is correct

    Downloading hundreds of files from SharePoint Online in a short period matches mass-download behaviour that Defender for Cloud Apps flags as potential exfiltration. The volume and compressed timeframe satisfy the suspicious-activity constraint in the stem, unlike routine single-file access, making it the strongest hunting query candidate.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.