nerdexam
Microsoft

SC-200 · Question #220

You have a Microsoft 365 E5 subscription that uses Microsoft Defender 365. You need to ensure that you can investigate threats by using data in the unified audit log of Microsoft Defender for Cloud…

The correct answer is C. the Office 365 connector. The unified audit log is a Microsoft 365 (Office 365) feature that records user and admin activity across Microsoft 365 services. To make this audit log data available within Microsoft Defender for Cloud Apps for threat investigation, you must first configure the Office 365…

Submitted by asante_acc· Apr 18, 2026Manage threat mitigation using Microsoft Defender XDR

Question

You have a Microsoft 365 E5 subscription that uses Microsoft Defender 365. You need to ensure that you can investigate threats by using data in the unified audit log of Microsoft Defender for Cloud Apps. What should you configure first?

Options

  • Athe User enrichment settings
  • Bthe Azure connector
  • Cthe Office 365 connector
  • Dthe Automatic log upload settings

How the community answered

(31 responses)
  • A
    13% (4)
  • B
    6% (2)
  • C
    77% (24)
  • D
    3% (1)

Explanation

The unified audit log is a Microsoft 365 (Office 365) feature that records user and admin activity across Microsoft 365 services. To make this audit log data available within Microsoft Defender for Cloud Apps for threat investigation, you must first configure the Office 365 connector. This connector establishes the integration between Defender for Cloud Apps and the Microsoft 365 unified audit log, enabling activity data ingestion. The Azure connector integrates Azure services (not the audit log), Automatic log upload is for firewall/proxy traffic logs, and User enrichment settings enhance user profile data - none of these provide access to the unified audit log.

Topics

#Microsoft Defender for Cloud Apps#Office 365 connector#Unified audit log#Threat investigation

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice