Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

Your team is using Microsoft 365 Defender advanced hunting to investigate a possible data exfiltration incident. The security team suspects that an internal attacker used a compromised SharePoint Online account to download sensitive files from multiple sites. You need to build a hunting query that identifies all file download activities from SharePoint Online for a specific user account over the past 7 days, and then calculates the total size of downloaded files. Which KQL query should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudAppEvents | where Application == 'SharePoint Online' and ActionType == 'FileDownloaded' and AccountDisplayName == 'targetuser@contoso.com' and Timestamp > ago(7d) | summarize TotalSize = sum(FileSize)

Ly filters SharePoint file download events (FileDownloaded) and sums the FileSize. Option A uses wrong action; Option C uses wrong table; Option D is for email.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CloudAppEvents | where Application == 'SharePoint Online' and ActionType == 'FileDownload' and AccountDisplayName == 'targetuser@contoso.com' and Timestamp > ago(7d) | summarize TotalSize = sum(FileSize)

    Why it's wrong here

    This query targets the correct CloudAppEvents table, which holds SharePoint Online activity, but the ActionType filter specifies 'FileDownload' instead of the actual action name 'FileDownloaded' as recorded in the unified audit log for file downloads. Because the literal value does not match any valid action type in CloudAppEvents, the filter silently returns zero rows, and the subsequent summarize operation computes an empty total size. This false negative makes the query invalid for measuring the user's downloaded data.

  • ✓

    CloudAppEvents | where Application == 'SharePoint Online' and ActionType == 'FileDownloaded' and AccountDisplayName == 'targetuser@contoso.com' and Timestamp > ago(7d) | summarize TotalSize = sum(FileSize)

    Why this is correct

    This query is correct because it uses the CloudAppEvents table, the authoritative table in Microsoft 365 Defender advanced hunting for cloud app activities, and filters on ActionType == 'FileDownloaded', which is the exact event name for file downloads in SharePoint Online. The AccountDisplayName filter isolates the target user's actions within the last 7 days, and summarize TotalSize = sum(FileSize) correctly aggregates the FileSize numeric column to yield the total bytes downloaded. It is the only option that combines the right table, accurate action type, and proper aggregation.

  • ✗

    EmailEvents | where Application == 'SharePoint Online' and ActionType == 'FileDownloaded' and AccountDisplayName == 'targetuser@contoso.com' and Timestamp > ago(7d) | summarize TotalSize = sum(FileSize)

    Why it's wrong here

    This query incorrectly queries the EmailEvents table, which is designed for email message records such as send, receive, and delivery events, typically related to phishing and mail flow analysis. SharePoint Online file download activity is never stored in EmailEvents, so even with the correct ActionType 'FileDownloaded', the where clause matches no rows. Additionally, EmailEvents does not include a FileSize column for cloud downloads, so sum(FileSize) would either fail or be meaningless; the source must be CloudAppEvents.

  • ✗

    FileEvents | where Application == 'SharePoint Online' and ActionType == 'FileDownloaded' and AccountDisplayName == 'targetuser@contoso.com' and Timestamp > ago(7d) | summarize TotalSize = sum(FileSize)

    Why it's wrong here

    This query mistakenly uses the FileEvents table, which captures file system activities at the endpoint level, such as file creation, modification, and deletion on a device. A download from SharePoint Online performed in a web browser is a cloud app event, not an endpoint file event, so Microsoft 365 Defender records it in CloudAppEvents. The FileEvents table lacks the Application field for cloud services and its ActionType enumerations are different, meaning the where clause filters on attributes that do not exist in this table. To track SharePoint downloads, you must query CloudAppEvents.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.