Microsoft 365 Administrator Expert MS-102 Practice Question
You have connected your Microsoft 365 tenant to Microsoft Defender for Cloud Apps (MDCA). A security alert notifies you that an Azure AD-registered application named Contoso-Reports was granted Organization.Read.All permission. You need to determine exactly who, when, and from where this permission was granted by using the MDCA activity log. Which filter combination should you apply first to quickly locate the relevant event in the activity log?
Activity type equals Consent to application and Application equals Contoso-Reports
Activity type equals Create service principal and App equals Azure Active Directory
Device tag equals Unmanaged and Activity type equals User login
Activity type equals OAuth privilege escalation and App equals Office 365
In the Defender for Cloud Apps activity log, the event that records a user or administrator granting OAuth permissions to an Azure AD application is "Consent to application." Filtering the log for this Activity type immediately narrows the results to permission-grant events only. Adding a filter for the Application ID or display name (Contoso-Reports) ensures that only events involving the suspicious app are shown. Once the single event is isolated, the log columns reveal the acting user (granted by), the date/time, the source IP address, and other context. The other options either reference activity types that are not written for OAuth consent (such as service principal creation or privilege escalation) or use filters (App equals Office 365, Device tag, etc.) that would return many unrelated events, making the investigation slower and potentially missing the consent event entirely.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the MDCA activity log used for?
Open an interactive chat with Bash
What does 'Consent to application' mean?
Open an interactive chat with Bash
How do 'Activity type' filters benefit investigations in MDCA?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Manage security and threats by using Microsoft Defender XDR
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .