Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that alerts when a user downloads more than 10 files from SharePoint Online within 10 minutes. This activity should be considered anomalous. Which type of policy should you create?

⚠ Common exam trap

MS-102 often tests whether candidates confuse Activity policies (threshold-based alerts on user actions) with Session policies (real-time access control) or Cloud Discovery policies (shadow IT visibility).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Activity policy

An Activity policy in Defender for Cloud Apps triggers alerts based on user activities such as file downloads, and supports thresholds and time windows. To alert when a user downloads more than 10 files from SharePoint Online within 10 minutes, you configure an Activity policy with the 'Download file' activity, a threshold of 10, and a 10-minute window. This matches the requirement exactly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud Discovery policy

    Why it's wrong here

    Cloud Discovery policies govern which unsanctioned apps appear in the discovered apps catalogue and their risk scores, based on traffic log analysis. They do not monitor per-user file download counts in SharePoint Online. Cloud Discovery tempts because it also processes activity data, but its scope is app sanctioning, not user behaviour thresholds.

  • ✓

    Activity policy

    Why this is correct

    Activity policies in Microsoft Defender for Cloud Apps evaluate user activity against thresholds and anomaly detection, so a rule triggering when more than ten SharePoint Online downloads occur within ten minutes matches this policy type.

  • ✗

    Session policy

    Why it's wrong here

    Session policies apply real-time proxy controls to active user sessions, such as blocking downloads or requiring step-up authentication, rather than generating alerts from aggregated activity thresholds. Anomaly detection policies evaluate activity volume over a window. Session policies tempt because they also target SharePoint file activity, but they act inline instead of alerting.

  • ✗

    App discovery policy

    Why it's wrong here

    App discovery policies analyse traffic logs to identify unsanctioned cloud services in use across the organisation, not user activity volumes within a sanctioned app. Anomaly detection policies count actions such as downloads per user over time. App discovery tempts because it also surfaces cloud app usage, but it catalogues services rather than flagging behaviour.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.