Courseiva

MS-102 Activity policy Practice Question

Your organization has deployed Microsoft Defender for Cloud Apps. You want to detect anomalous behavior such as impossible travel for users accessing cloud apps. You need to configure the appropriate policy. Which policy type should you create?

⚠ Common exam trap

MS-102 often tests the confusion between activity policies (behavioral anomaly detection) and session policies (real-time access control), so candidates pick session policy when the question mentions 'anomalous behavior'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Activity policy

Activity policies in Microsoft Defender for Cloud Apps are designed to monitor user activity across cloud apps and trigger alerts or governance actions on anomalous behavior, including impossible travel, suspicious IP addresses, and unusual file downloads. Creating an activity policy with the 'Impossible travel' template directly detects the scenario described. This is the correct policy type for behavioral anomaly detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    App discovery policy

    Why it's wrong here

    App discovery policies catalogue unsanctioned cloud services from traffic logs; they do not model per-user behavioural baselines. Anomaly detection for impossible travel requires an anomaly detection policy, which learns each user's normal sign-in patterns. Discovery is tempting because it also targets cloud apps, but its purpose is shadow-IT visibility, not user behaviour analytics.

  • ✓

    Activity policy

    Why this is correct

    Activity policies evaluate user activity events against behavioural baselines, so impossible travel and other anomalies trigger alerts or governance actions. They operate on the activity log rather than file content, matching the requirement to detect anomalous cloud app access.

  • ✗

    Session policy

    Why it's wrong here

    Session policies apply real-time controls such as blocking downloads or DLP inspection on active sessions; they do not evaluate sign-in patterns for anomalies. Session policies suit enforcing conditional access and data controls during user sessions, not detecting impossible travel.

  • ✗

    File policy

    Why it's wrong here

    File policies scan and govern stored content for sensitive information or malware; they do not assess user sign-in geography or velocity. File policies suit data classification, DLP enforcement and quarantine of documents in connected cloud apps.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.