SC-200 Perform threat hunting Practice Question
Your team is conducting a threat hunt for data exfiltration using Microsoft Defender for Cloud Apps. Which activity is most suspicious and should be included in the hunting query?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A user downloading hundreds of files from SharePoint Online in a short time.
Mass download of hundreds of files from SharePoint Online in a short time is a classic indicator of data exfiltration. Option D is correct. Option A is incorrect because viewing files is normal user activity and not indicative of exfiltration. Option B is incorrect because downloading a single file is routine and not suspicious. Option C is incorrect because sharing a file with an internal colleague is typical collaboration and less likely to be exfiltration than mass downloads or external sharing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A user viewing files in OneDrive for Business.
Why it's wrong here
Viewing files in OneDrive is read-only access by the data owner, producing no transfer of data outside the tenant. It tempts because OneDrive activity appears in Defender for Cloud Apps logs, but viewing lacks the volume, destination and exfiltration indicators that distinguish suspicious activity from normal access.
- ✗
A user downloading a single file from SharePoint Online.
Why it's wrong here
A single SharePoint download is routine user behaviour, so it generates no exfiltration signal; bulk downloads or downloads to unmanaged devices are the suspicious patterns. It tempts because SharePoint holds sensitive data and downloads can precede exfiltration, but one file lacks the volume or anomaly that Defender for Cloud Apps hunting queries target.
- ✗
A user sharing a file with an internal colleague.
Why it's wrong here
Internal sharing stays within the tenant boundary, so no data leaves the organisation and no exfiltration alert fires. It tempts because file-sharing activity is logged and auditable, but external or anonymous sharing links are the suspicious events; internal collaboration is expected and would not warrant hunting.
- ✓
A user downloading hundreds of files from SharePoint Online in a short time.
Why this is correct
Downloading hundreds of files from SharePoint Online in a short period matches mass-download behaviour that Defender for Cloud Apps flags as potential exfiltration. The volume and compressed timeframe satisfy the suspicious-activity constraint in the stem, unlike routine single-file access, making it the strongest hunting query candidate.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.