Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your organization uses Microsoft Defender for Cloud Apps. You want to set up a policy that automatically suspends a user if they download more than 100 files from SharePoint Online within 10 minutes. Which type of policy should you create?

⚠ Common exam trap

Candidates often confuse Activity policies with Session policies, mistakenly thinking session-level controls can enforce download limits, but session policies only act on real-time actions within a single session and cannot trigger user suspension based on aggregated activity history.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Activity policy

An Activity policy in Microsoft Defender for Cloud Apps monitors user activities across connected apps and can trigger automated actions, such as suspending a user, when a specific threshold of downloads from SharePoint Online is exceeded within a defined time window. This policy type is designed to detect anomalous behavior patterns like mass file downloads, making it the correct choice for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Session policy

    Why it's wrong here

    Session policies in Defender for Cloud Apps are evaluated in real time as a user accesses a cloud app, using Conditional Access App Control to allow, block, or restrict specific actions during that session. They are not designed to react after the fact to a detected anomaly, so they cannot suspend a user account once suspicious activity has already occurred. Suspension is a governance action, not a session-level access control.

  • ✓

    Activity policy

    Why this is correct

    Activity policies monitor user, admin, and sign-in activities for anomalous patterns, such as impossible travel, mass download, or failed sign-ins. When a threshold or heuristic is breached, the policy can automatically trigger a governance action, including suspending the affected user account. This makes the Activity policy the correct option for post-detection user suspension, as it reacts to logged activity rather than controlling the live session.

  • ✗

    File policy

    Why it's wrong here

    File policies are scoped strictly to file objects, scanning cloud storage for malware, sharing violations, or sensitive data exposure via the content inspection engine. They evaluate attributes like file name, extension, owner, or external collaborators, not behavioral patterns of user activity. Consequently, they cannot raise an alert about a user's anomalous behavior and therefore cannot trigger a user suspension action.

  • ✗

    App discovery policy

    Why it's wrong here

    App discovery policies analyze network traffic to identify shadow IT, unsanctioned cloud apps, or risky app usage by examining firewall and proxy logs. Their purpose is to classify applications and assess their risk score, not to inspect individual user activities within already-sanctioned apps. Because they do not process user activity anomalies, they have no mechanism to suspend a user when suspicious behavior is detected.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.