Investigate Microsoft 365 activities to identify threats
6 practice questions under this official exam objective (SC-200) — each with the community-verified answer, a full option-by-option explanation and instant feedback.
Analyzing all Microsoft Graph API attack tactics through the MicrosoftGraphActivityLogs table
When an attacker uses the Microsoft Graph API as a vector, every tactic expressed as a Graph API call is recorded in the MicrosoftGraphActivityLogs ad
Analyzing Microsoft Graph API attack tactics through the MicrosoftGraphActivityLogs advanced-hunting table
When an attacker uses the Microsoft Graph API as a vector, all Graph API call activity is recorded in the MicrosoftGraphActivityLogs table, so every t
Reducing returned records from Defender before export so Excel builds the audit JSON columns
To ensure Excel generates columns for specific JSON properties, you modify the Defender audit-search criteria to return fewer records before exporting
Reducing rows before the JSON transform so Excel generates the needed audit columns
To make Excel create columns for specific JSON properties in an audit export, you reduce the number of rows (for example by filtering) so that records
Why increasing audit-search record count does not fix missing JSON columns in Excel
When Excel's Get & Transform fails to create columns for specific JSON properties in an audit export, increasing the number of returned records does n
Streaming Microsoft Graph activity logs to a third-party SIEM via Azure Event Hubs
To stream Microsoft Graph activity logs to a third-party SIEM with minimal effort, stream them to an Azure Event Hubs namespace, which is the document