MS-102 Activity policy Practice Question
Your organization has deployed Microsoft Defender for Cloud Apps. You want to detect anomalous behavior such as impossible travel for users accessing cloud apps. You need to configure the appropriate policy. Which policy type should you create?
⚠ Common exam trap
MS-102 often tests the confusion between activity policies (behavioral anomaly detection) and session policies (real-time access control), so candidates pick session policy when the question mentions 'anomalous behavior'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Activity policy
Activity policies in Microsoft Defender for Cloud Apps are designed to monitor user activity across cloud apps and trigger alerts or governance actions on anomalous behavior, including impossible travel, suspicious IP addresses, and unusual file downloads. Creating an activity policy with the 'Impossible travel' template directly detects the scenario described. This is the correct policy type for behavioral anomaly detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
App discovery policy
Why it's wrong here
App discovery policies catalogue unsanctioned cloud services from traffic logs; they do not model per-user behavioural baselines. Anomaly detection for impossible travel requires an anomaly detection policy, which learns each user's normal sign-in patterns. Discovery is tempting because it also targets cloud apps, but its purpose is shadow-IT visibility, not user behaviour analytics.
- ✓
Activity policy
Why this is correct
Activity policies evaluate user activity events against behavioural baselines, so impossible travel and other anomalies trigger alerts or governance actions. They operate on the activity log rather than file content, matching the requirement to detect anomalous cloud app access.
- ✗
Session policy
Why it's wrong here
Session policies apply real-time controls such as blocking downloads or DLP inspection on active sessions; they do not evaluate sign-in patterns for anomalies. Session policies suit enforcing conditional access and data controls during user sessions, not detecting impossible travel.
- ✗
File policy
Why it's wrong here
File policies scan and govern stored content for sensitive information or malware; they do not assess user sign-in geography or velocity. File policies suit data classification, DLP enforcement and quarantine of documents in connected cloud apps.
Go deeper
Related to this question
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.