MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization is implementing Microsoft Defender for Cloud Apps. You need to configure anomaly detection policies to alert when a user downloads an unusually large number of files from SharePoint Online. Which data source should you connect to enable this detection?
⚠ Common exam trap
It's easy for candidates to confuse Microsoft 365 Defender portal (a viewing/management interface) with a data source, or assume that Microsoft Entra ID logs contain sufficient activity data for file-level anomaly detection, when in fact only the App connector provides the necessary SharePoint Online activity metadata.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
App connector for SharePoint Online
To detect anomalous file downloads from SharePoint Online, Microsoft Defender for Cloud Apps requires direct integration with the service via an App connector. The App connector for SharePoint Online (option B) enables the collection of metadata and activity logs necessary for anomaly detection policies, such as the 'Unusual file download by a user' policy. Without this connector, Defender for Cloud Apps cannot monitor SharePoint Online activities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
API connector for custom apps
Why it's wrong here
The API connector in Microsoft Defender for Cloud Apps is intended for custom-built or legacy line-of-business applications that expose a REST API, not for natively supported SaaS apps. It requires manually defining the API endpoint and activity schema, and it cannot interpret SharePoint's native file-download event structure. Because SharePoint Online already has a dedicated App connector that pulls the exact activity data needed, using a custom API connector here would be both redundant and technically incorrect.
- ✓
App connector for SharePoint Online
Why this is correct
The App connector for SharePoint Online is the correct data source because it uses the Office 365 Management Activity API to capture user-level file activities such as downloads, uploads, edits, and permissions changes from SharePoint. When enabled in Microsoft Defender for Cloud Apps, it continuously ingests these events, which are essential for anomaly detection scenarios like unusual mass downloading or impossible travel. This connector directly provides the file-level context that sign-in logs and management portals lack, making it the single authoritative source for this requirement.
- ✗
Microsoft 365 Defender portal
Why it's wrong here
The Microsoft 365 Defender portal is the unified incident-response console that presents alerts and correlated detections from Microsoft 365 Defender, including Defender for Cloud Apps, but it is not a data source. Enabling or visiting the portal does not generate any SharePoint activity logs; it merely consumes signals already ingested by connectors and transmits them to security operators. Thus, while you would view the resulting anomaly alerts in this portal, it cannot be used to supply file-download activity data for detection in the first place.
- ✗
Microsoft Entra ID logs
Why it's wrong here
Microsoft Entra ID (formerly Azure AD) sign-in logs capture authentication events such as user, application, IP address, and sign-in outcome, but they do not include individual file operations like downloading a document from SharePoint Online. They can help identify identity-level anomalies, such as impossible travel across sign-ins, but they lack the resource-level detail needed to detect unusual or malicious access to specific SharePoint content. The SharePoint Online connector is the source that supplies the required file-activity data, making Entra ID logs an incomplete and unsuitable replacement for this scenario.
Go deeper
Related to this question
Learn chapter
Intune and Conditional Access Integration
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
SharePoint Online
SharePoint Online is a cloud-based collaboration platform from Microsoft that lets teams create, store, organize, and share content securely from anywhere.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.