Microsoft Security Operations Analyst Associate SC-200 Practice Question
A security incident involves sensitive files that were downloaded from a SharePoint Online site by an external guest account. You must identify every download event that occurred during the last 30 days by using PowerShell. Which action meets the requirement with the least administrative effort?
Query Azure AD sign-in logs by using Microsoft Graph to find sign-ins from the guest account during the last 30 days.
Use the Search-UnifiedAuditLog cmdlet with the parameters -RecordType SharePointFileOperation and -Operations FileDownloaded, scoped to the guest user account.
Run a Content Search in the Microsoft Purview compliance portal, specifying the SharePoint site URL and a keyword query of "guest download".
Execute a Microsoft 365 Defender advanced hunting query against the DeviceFileEvents table to locate FileDownloaded actions.
The Microsoft 365 unified audit log records all SharePoint file operations. Running the Search-UnifiedAuditLog cmdlet and filtering for the SharePointFileOperation record type and the FileDownloaded operation returns a list of every file download event, including those performed by guest users, without requiring additional tooling or elevated administrative access. Azure AD sign-in logs do not record file downloads, Content Search does not provide event-level audit data, and Microsoft 365 Defender advanced hunting queries SharePoint activity only when the Defender for Cloud Apps integration is enabled.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Search-UnifiedAuditLog cmdlet?
Open an interactive chat with Bash
What does the RecordType parameter do in Search-UnifiedAuditLog?
Open an interactive chat with Bash
How is Microsoft Defender for Cloud Apps involved in logging SharePoint file actions?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .