Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security analyst is investigating a potential compromise involving a user's cloud application activity. They need to quickly identify all activities performed by a specific user across various sanctioned cloud apps, including login attempts, file downloads, and administrative actions, within the last 24 hours. Which Microsoft Defender for Cloud Apps (MDCAS) feature provides the most efficient way to achieve this comprehensive view?
- ASanctioned app connectors
- BActivity log
- CCloud Discovery dashboard
- DFiles page
Show answer & explanationAnswer & explanation
Correct answer: B. Activity log
The Activity log in Microsoft Defender for Cloud Apps provides a centralized, detailed record of all user and admin activities across connected cloud applications. It allows for filtering by user, activity type, and time range, making it the most efficient tool for this investigation.
Why the other options are wrong
- A. Sanctioned app connectors enable data collection, but the Activity log is where that collected activity data is viewed and analyzed.
- C. The Cloud Discovery dashboard focuses on shadow IT and discovered apps, not detailed activity for sanctioned apps.
- D. The Files page is for investigating files and their sharing, not a comprehensive view of all user activities.
MDCAS Activity Log
A central repository in Microsoft Defender for Cloud Apps that records and displays detailed user and administrative activities across all connected sanctioned cloud applications.
- Aggregates activities from multiple apps.
- Allows filtering by user, app, activity type, and time.
- Essential for incident investigation and auditing.
Memory trick: The Activity Log is like a detective's journal, recording every single step a user takes in the cloud.