Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security analyst is investigating a potential insider threat where an employee is suspected of exfiltrating sensitive intellectual property. The analyst needs to understand the user's activities across various cloud applications, including file access, download patterns, and unusual login locations, over the past month. Which Microsoft Defender for Cloud Apps (MDCAS) feature provides the most comprehensive historical record of user activities across all connected cloud applications?

  1. AAlerts page
  2. BCloud Discovery dashboard
  3. CActivity log
  4. DFile page
Show answer & explanation

Correct answer: C. Activity log

The Activity log in Microsoft Defender for Cloud Apps provides a comprehensive, searchable, and filterable record of all user and admin activities across all connected cloud applications, making it ideal for investigating historical user behavior related to data exfiltration or unusual access.

Why the other options are wrong

  • A. The Alerts page shows triggered alerts, but not the raw, comprehensive activity data needed for a deep investigation into all user actions.
  • B. The Cloud Discovery dashboard focuses on identifying and assessing shadow IT, not detailed individual user activity across sanctioned apps.
  • D. The File page focuses on files stored in connected cloud apps (e.g., sensitive content, sharing), but doesn't provide the full scope of user activities (like logins, downloads, app access) across all apps.

MDCAS Activity Log

The Microsoft Defender for Cloud Apps Activity log provides a granular, searchable record of all user and admin activities performed across connected cloud applications.

  • Captures a wide range of activities (logins, file access, downloads, admin actions).
  • Centralized view across all monitored cloud apps.
  • Essential for forensic investigations and auditing.

Memory trick: To see *everything* a user did, you need to check the full 'Activity Log', not just a summary or alerts.

More Mitigate threats using Microsoft Defender XDR questions