Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization is implementing Microsoft Defender for Cloud Apps. You need to configure anomaly detection policies to alert when a user downloads an unusually large number of files from SharePoint Online. Which data source should you connect to enable this detection?

⚠ Common exam trap

It's easy for candidates to confuse Microsoft 365 Defender portal (a viewing/management interface) with a data source, or assume that Microsoft Entra ID logs contain sufficient activity data for file-level anomaly detection, when in fact only the App connector provides the necessary SharePoint Online activity metadata.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

App connector for SharePoint Online

To detect anomalous file downloads from SharePoint Online, Microsoft Defender for Cloud Apps requires direct integration with the service via an App connector. The App connector for SharePoint Online (option B) enables the collection of metadata and activity logs necessary for anomaly detection policies, such as the 'Unusual file download by a user' policy. Without this connector, Defender for Cloud Apps cannot monitor SharePoint Online activities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    API connector for custom apps

    Why it's wrong here

    The API connector in Microsoft Defender for Cloud Apps is intended for custom-built or legacy line-of-business applications that expose a REST API, not for natively supported SaaS apps. It requires manually defining the API endpoint and activity schema, and it cannot interpret SharePoint's native file-download event structure. Because SharePoint Online already has a dedicated App connector that pulls the exact activity data needed, using a custom API connector here would be both redundant and technically incorrect.

  • ✓

    App connector for SharePoint Online

    Why this is correct

    The App connector for SharePoint Online is the correct data source because it uses the Office 365 Management Activity API to capture user-level file activities such as downloads, uploads, edits, and permissions changes from SharePoint. When enabled in Microsoft Defender for Cloud Apps, it continuously ingests these events, which are essential for anomaly detection scenarios like unusual mass downloading or impossible travel. This connector directly provides the file-level context that sign-in logs and management portals lack, making it the single authoritative source for this requirement.

  • ✗

    Microsoft 365 Defender portal

    Why it's wrong here

    The Microsoft 365 Defender portal is the unified incident-response console that presents alerts and correlated detections from Microsoft 365 Defender, including Defender for Cloud Apps, but it is not a data source. Enabling or visiting the portal does not generate any SharePoint activity logs; it merely consumes signals already ingested by connectors and transmits them to security operators. Thus, while you would view the resulting anomaly alerts in this portal, it cannot be used to supply file-download activity data for detection in the first place.

  • ✗

    Microsoft Entra ID logs

    Why it's wrong here

    Microsoft Entra ID (formerly Azure AD) sign-in logs capture authentication events such as user, application, IP address, and sign-in outcome, but they do not include individual file operations like downloading a document from SharePoint Online. They can help identify identity-level anomalies, such as impossible travel across sign-ins, but they lack the resource-level detail needed to detect unusual or malicious access to specific SharePoint content. The SharePoint Online connector is the source that supplies the required file-activity data, making Entra ID logs an incomplete and unsuitable replacement for this scenario.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.