MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that alerts when a user downloads more than 10 files from SharePoint Online within 10 minutes. This activity should be considered anomalous. Which type of policy should you create?
⚠ Common exam trap
MS-102 often tests whether candidates confuse Activity policies (threshold-based alerts on user actions) with Session policies (real-time access control) or Cloud Discovery policies (shadow IT visibility).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Activity policy
An Activity policy in Defender for Cloud Apps triggers alerts based on user activities such as file downloads, and supports thresholds and time windows. To alert when a user downloads more than 10 files from SharePoint Online within 10 minutes, you configure an Activity policy with the 'Download file' activity, a threshold of 10, and a 10-minute window. This matches the requirement exactly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Discovery policy
Why it's wrong here
Cloud Discovery policies govern which unsanctioned apps appear in the discovered apps catalogue and their risk scores, based on traffic log analysis. They do not monitor per-user file download counts in SharePoint Online. Cloud Discovery tempts because it also processes activity data, but its scope is app sanctioning, not user behaviour thresholds.
- ✓
Activity policy
Why this is correct
Activity policies in Microsoft Defender for Cloud Apps evaluate user activity against thresholds and anomaly detection, so a rule triggering when more than ten SharePoint Online downloads occur within ten minutes matches this policy type.
- ✗
Session policy
Why it's wrong here
Session policies apply real-time proxy controls to active user sessions, such as blocking downloads or requiring step-up authentication, rather than generating alerts from aggregated activity thresholds. Anomaly detection policies evaluate activity volume over a window. Session policies tempt because they also target SharePoint file activity, but they act inline instead of alerting.
- ✗
App discovery policy
Why it's wrong here
App discovery policies analyse traffic logs to identify unsanctioned cloud services in use across the organisation, not user activity volumes within a sanctioned app. Anomaly detection policies count actions such as downloads per user over time. App discovery tempts because it also surfaces cloud app usage, but it catalogues services rather than flagging behaviour.
Go deeper
Related to this question
Learn chapter
Microsoft Defender for Cloud Apps Administration
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
SharePoint Online
SharePoint Online is a cloud-based collaboration platform from Microsoft that lets teams create, store, organize, and share content securely from anywhere.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.