Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security analyst is investigating a potential insider threat scenario. An employee, who recently submitted their resignation, accessed a highly sensitive SharePoint Online document library and downloaded a large number of files. The organization has Microsoft Defender for Cloud Apps (MDCAS) integrated with SharePoint Online. The analyst needs to review a detailed log of all activities performed by this specific user within SharePoint Online, including file access, downloads, and any modifications, to understand the full scope of their actions. Which MDCAS portal feature provides this detailed activity log?

  1. AActivity log
  2. BFiles page
  3. CAlerts page
  4. DCloud Discovery dashboard
Show answer & explanation

Correct answer: A. Activity log

The Activity log in Microsoft Defender for Cloud Apps provides a comprehensive, searchable, and filterable record of all activities performed by users within connected cloud applications, including SharePoint Online. This is the primary location to investigate specific user actions like file access, downloads, and modifications.

Why the other options are wrong

  • B. The Files page focuses on discovered sensitive files and their attributes, not user activities performed on those files.
  • C. The Alerts page shows triggered policy alerts, but not a full, chronological list of all user activities.
  • D. Cloud Discovery dashboard identifies and assesses shadow IT apps, not detailed user activity within sanctioned apps.

MDCAS Activity Log

A central feature in Microsoft Defender for Cloud Apps that provides a detailed, searchable, and filterable record of all user and admin activities performed across connected cloud applications.

  • Captures a wide range of activities (logins, file actions, admin changes).
  • Supports advanced filtering and searching.
  • Essential for forensic investigations and auditing.

Memory trick: The Activity Log is your diary of who did what, where, and when in the cloud.

More Mitigate threats using Microsoft Defender XDR questions