🔥 40% Off Crucial Exams Memberships — This Week Only

3 days, 13 hours remaining!

Microsoft Security Operations Analyst Associate SC-200 Practice Question

You are investigating a suspected mailbox compromise. Your goal is to verify whether anyone other than the mailbox owner has viewed messages in the mailbox during the last seven days and to learn the source IP address that was used. You decide to run a search in the Microsoft Purview compliance portal's unified audit log. Which audit-log activity and field combination will give you the required evidence in a single record?

  • Filter for the AzureActiveDirectoryStsLogon activity and read the IPAddress field.

  • Filter for the MailboxLogin activity and read the DeviceId field.

  • Filter for the MailItemsAccessed activity and read the ClientIP field.

  • Filter for the ExchangeAdmin activity and read the MailboxAccessType field.

Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot