MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a Microsoft 365 administrator for a company that uses Microsoft Defender for Cloud Apps. The security team wants to detect when users download a large number of files from SharePoint Online in a short period, which could indicate data exfiltration. You need to create a policy to alert on this activity. What should you do?
⚠ Common exam trap
The trap here is assuming that file policies or session policies can detect download volume, but only activity policies track user actions with customizable thresholds.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an activity policy with a filter for 'Download file' and a threshold for the number of files.
Activity policies in Microsoft Defender for Cloud Apps are designed to monitor user activities and can be configured with filters and thresholds to detect specific behaviors like mass file downloads. This provides the precise alerting needed for potential data exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set up an anomaly detection policy for unusual file access.
Why it's wrong here
Anomaly detection policies use machine learning to detect unusual behavior, but they are not customizable with specific thresholds for the number of downloads. They might detect the activity eventually, but they do not provide the precise, threshold-based alerting required in this scenario.
- ✓
Create an activity policy with a filter for 'Download file' and a threshold for the number of files.
Why this is correct
Activity policies in Microsoft Defender for Cloud Apps monitor user activities across connected apps. By filtering for 'Download file' and setting a threshold on the number of files within a time window, you can detect mass download behavior indicative of exfiltration. This directly addresses the requirement.
- ✗
Configure a session policy to block downloads from SharePoint Online.
Why it's wrong here
Session policies control real-time access and can block downloads, but they do not alert based on a threshold of downloads. They are used for conditional access app control, not for detecting anomalous download volumes. This would prevent downloads rather than detect the suspicious activity.
- ✗
Create a file policy with a filter for file name and a threshold for file size.
Why it's wrong here
File policies are used to scan files for sensitive content or malware, not to monitor user download activity. They do not track the number of files downloaded by a user in a time period. Therefore, a file policy would not detect the mass download scenario described.
Go deeper
Related to this question
Learn chapter
Exchange Mobile Device Policies (OWA)
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
SharePoint Online
SharePoint Online is a cloud-based collaboration platform from Microsoft that lets teams create, store, organize, and share content securely from anywhere.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.