exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 8 question 3 discussion

Actual exam question from Microsoft's SC-200
Question #: 3
Topic #: 12
[All SC-200 Questions]

HOTSPOT -
You need to create an advanced hunting query to investigate the executive team issue.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Beitran
Highly Voted 3 years, 5 months ago
CloudAppEvents doesn't have the FolderPath column, so it's probably DeviceFileEvents: https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-devicefileevents-table?view=o365-worldwide
upvoted 23 times
teehex
3 years, 3 months ago
Read it bro https://techcommunity.microsoft.com/t5/microsoft-365-defender/hunt-across-cloud-app-activities-with-microsoft-365-defender/ba-p/1893857 CloudAppEvents replaced AppFileEvents so everything AppFireEvents had is included in CloudAppEvents
upvoted 22 times
Metasploit
2 years ago
Not everything. You can see in their examples within your posted url where the changes are for one of their queries. The appfileevents had the folderpath column but the updated cloudappevents query did not have the folderpath column as it is not part of cloudappevents.
upvoted 6 times
...
AlaReAla
3 years ago
I too will go with @Teehex. Quoting the text from shared URL for your ease: "The AppFileEvents table, which contains file activities from these applications, will stop getting populated with new data in early 2021. Activities involving these applications, including file activities, will be recorded in the new CloudAppEvents table"
upvoted 8 times
...
...
...
fr54fr
Highly Voted 3 years, 4 months ago
users hunting through file-related activities in cloud services should use the CloudAppEvents table instead [Column name: ActivityObjects - List of objects, such as files or folders, that were involved in the recorded activity] https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-cloudappevents-table?view=o365-worldwide
upvoted 13 times
madhatter
3 years, 4 months ago
Its easy to get confused with File properties but this question asks for "data access, download, or deletion for Microsoft Cloud App Security-protected applications" Provided answer most likely correct "CloudAppEvents"
upvoted 5 times
...
...
kazaki
Most Recent 8 months, 2 weeks ago
as usual outdated question with outdated answers DeviceFileEvents is the answer
upvoted 5 times
...
estyj
10 months ago
Folderpath column not in cloudappevents. https://techcommunity.microsoft.com/t5/microsoft-365-defender/hunt-across-cloud-app-activities-with-microsoft-365-defender/ba-p/1893857 article published 2020 https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-devicefileevents-table?view=o365-worldwide article updated 11/2023 so will go with AppFileEvents.
upvoted 1 times
...
danb67
1 year ago
Query is wrong. Neither of the 3 tables listed has the 4 columns required. 4 columns required are FileName, FolderPath, ActionType, AccountDisplayname. Check this for yourself. DeviceProcessEvents comes closest. That has FileName, FolderPath, ActionType and 'acccountname' columns I think there are errors in the given query
upvoted 1 times
...
Anil0512
1 year, 1 month ago
DeviceFileEvents & Count
upvoted 3 times
...
donathon
1 year, 2 months ago
Correct cloudappevents does not have the needed columns.
upvoted 2 times
danb67
1 year ago
True but DeviceFileEvents does not have all the needed columns either. DeviceFileEvents does not have the AccountDipslayName column. So I think this query is wrong altogether.
upvoted 1 times
...
...
wsrudmen
1 year, 8 months ago
It's: DeviceFileEvents count() - CloudAppEvents ○ The CloudAppEvents table in the advanced hunting schema contains information about activities in various cloud apps and services covered by Microsoft Defender for Cloud Apps ○ CloudAppEvents does not have FileName and FolderPath - DeviceFileEvents ○ The DeviceFileEvents table in the advanced hunting schema contains information about file creation, modification, and other file system events - DeviceProcessEvents The DeviceProcessEvents table in the advanced hunting schema contains information about process creation and related events.
upvoted 5 times
...
Apocalypse03
1 year, 10 months ago
Answers are correct: CloudAppEvents | where timeStamp > ago(2d) | where ActionType in ("Data Access", "Data Download", "Data Deletion") | summarize activityCount = count() by FolderPath, FileName, ActionType, AccountDisplayName | where activityCount > 5
upvoted 6 times
theplaceholder
1 year, 3 months ago
how are you finding FolderPath and FileName in CloudAppEvents? they're not there in my workspace
upvoted 3 times
...
Apocalypse03
1 year, 10 months ago
This query will filter the CloudAppEvents data by time (using the ago function to only include events from the past 48 hours), action type (using the in operator to include only data access, data download, or data deletion actions), and count the number of activities per file (using the summarize operator and the count() function). Finally, it will filter the results to only include files with more than five activities (using the where clause and the activityCount column).
upvoted 2 times
danb67
1 year ago
But the CloudAppEvents table does not have the FileName or FolderName columns so your query does not work. The DeviceFileEvents does not have all the needed columns either. DeviceFileEvents does not have the AccountDipslayName column.
upvoted 1 times
...
...
...
ACSC
1 year, 11 months ago
DeviceFileEvents Timestamp FileName FolderPath Count() https://learn.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-devicefileevents-table?view=o365-worldwide CloudAppEvents does not have FileName and FolderPath
upvoted 7 times
...
Davanitz
1 year, 11 months ago
These should be the right query since FolderPath and FileName don't exist in CloudAppEvents. CloudAppEvents | where Timestamp > ago(2d) | summarize activityCount = count() by ObjectName, ActionType, AccountDisplayName | where activityCount > 5
upvoted 2 times
...
hanyahmed
2 years, 2 months ago
It is correct answer. first answer : CloudAppEvents --> Yes Events involving accounts and objects in Office 365 and other cloud apps and services DeviceFileEvents --> No because it doesn't have involving accounts. File creation, modification, and other file system events From <https://docs.microsoft.com/en-us/learn/modules/query-logs-azure-sentinel/5-understand-microsoft-365-defender-tables> Second answer : count
upvoted 3 times
...
feln
2 years, 7 months ago
Nevermind my last comment
upvoted 1 times
...
feln
2 years, 7 months ago
So it says 'where timestamp > ago (2d)' and we're looking for events in the last 48h ? Doesn't look right does it? Shouldn't it be 'where timestamp < ago (2d)?
upvoted 1 times
...
subhuman
2 years, 7 months ago
Answer is correct : CloudAppEvents and count "The AppFileEvents table, which contains file activities from these applications, will stop getting populated with new data in early 2021. Activities involving these applications, including file activities, will be recorded in the new CloudAppEvents table."
upvoted 4 times
...
Contactfornitish
2 years, 8 months ago
Cloud app events + Count
upvoted 5 times
...
kakakayayaya
2 years, 10 months ago
In modern environment none of this answers are correct.
upvoted 3 times
kakakayayaya
2 years, 10 months ago
DeviceProcessEvents and DeficeFileEvents doesn't have AccountDisplayName column CloudAppEvents doesn't have FolderPath and Filename column.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago