MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You need to configure Microsoft Defender for Cloud Apps to detect anomalous user behavior such as impossible travel. Which type of policy should you create?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anomaly detection policy
Anomaly detection policy. In Microsoft Defender for Cloud Apps, anomaly detection policies are specifically designed to identify unusual user behaviors, such as impossible travel (login from geographically distant locations within a short time), unusual activity patterns, and other security anomalies. Option A (Access policy) is incorrect because it enforces access controls based on conditions like location or device, rather than detecting anomalies. Option B (Session policy) is incorrect as it monitors and controls real-time application sessions, not anomaly detection. Option D (File policy) is incorrect because it focuses on data protection by applying rules to files stored in cloud apps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Access policy
Why it's wrong here
Anomaly detection policies in Microsoft Defender for Cloud Apps generate alerts on impossible travel and other behavioural deviations; access policies instead enforce session or sign-in controls in real time. Access policies suit blocking downloads or requiring reauthentication for specific apps, not surfacing anomalous activity.
- ✗
Session policy
Why it's wrong here
Session policies apply real-time controls to user sessions, such as blocking downloads or proxy actions, after access is granted. Anomaly detection policies evaluate activity against behavioural baselines and raise alerts, which is what impossible travel requires.
- ✓
Anomaly detection policy
Why this is correct
Anomaly detection policies in Microsoft Defender for Cloud Apps baseline each user's normal activity and raise alerts on deviations such as impossible travel, satisfying the requirement to detect anomalous behaviour. Unlike activity policies, which trigger on predefined matching criteria, they use behavioural analytics, so no manual rule logic is needed.
- ✗
File policy
Why it's wrong here
File policies scan and govern content stored in connected cloud services, matching sensitive data or applying labels. They inspect documents rather than user sign-in patterns, so impossible travel detection needs an anomaly detection policy instead.
Go deeper
Related to this question
Learn chapter
Entra ID Entitlement Management and Access Packages
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.