Investigate Microsoft 365 activities to identify threats

6 practice questions under this official exam objective (SC-200) — each with the community-verified answer, a full option-by-option explanation and instant feedback.

SC-200 A-grade

Analyzing all Microsoft Graph API attack tactics through the MicrosoftGraphActivityLogs table

When an attacker uses the Microsoft Graph API as a vector, every tactic expressed as a Graph API call is recorded in the MicrosoftGraphActivityLogs ad

4 comments
SC-200 A-grade

Analyzing Microsoft Graph API attack tactics through the MicrosoftGraphActivityLogs advanced-hunting table

When an attacker uses the Microsoft Graph API as a vector, all Graph API call activity is recorded in the MicrosoftGraphActivityLogs table, so every t

4 comments
SC-200 A-grade

Reducing returned records from Defender before export so Excel builds the audit JSON columns

To ensure Excel generates columns for specific JSON properties, you modify the Defender audit-search criteria to return fewer records before exporting

3 comments
SC-200 A-grade

Reducing rows before the JSON transform so Excel generates the needed audit columns

To make Excel create columns for specific JSON properties in an audit export, you reduce the number of rows (for example by filtering) so that records

3 comments
SC-200 A-grade

Why increasing audit-search record count does not fix missing JSON columns in Excel

When Excel's Get & Transform fails to create columns for specific JSON properties in an audit export, increasing the number of returned records does n

3 comments
SC-200 A-grade

Streaming Microsoft Graph activity logs to a third-party SIEM via Azure Event Hubs

To stream Microsoft Graph activity logs to a third-party SIEM with minimal effort, stream them to an Azure Event Hubs namespace, which is the document

3 comments