Courseiva

How to Create an Anomaly Detection Policy for Mass File Downloads from SharePoint Online

Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that automatically alerts when a user downloads more than 100 files from SharePoint Online in 10 minutes. What type of policy should you create?

Quick Answer

The correct answer is an anomaly detection policy because this policy type is specifically designed to identify unusual patterns in user behavior, such as a mass file download from SharePoint Online that exceeds a defined threshold like 100 files in 10 minutes. Anomaly detection policies in Microsoft Defender for Cloud Apps leverage machine learning to establish a baseline of normal activity and then trigger alerts when deviations occur, making them the ideal tool for detecting potential data exfiltration or compromised accounts. On the Microsoft 365 Administrator MS-102 exam, this question tests your understanding of how to differentiate between policy types based on their purpose; a common trap is confusing anomaly detection with session policies, which control real-time access but do not monitor download volume thresholds. Remember the memory tip: "Anomaly for anomaly" — if the goal is to catch abnormal behavior like a sudden spike in downloads, always choose the anomaly detection policy.

⚠ Common exam trap

Candidates often confuse anomaly detection policies with session policies, mistakenly thinking session policies can alert on cumulative activity, when in fact session policies only enforce real-time controls during an active session.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Anomaly detection policy

An anomaly detection policy in Microsoft Defender for Cloud Apps is designed to identify unusual user behavior, such as a user downloading over 100 files from SharePoint Online within 10 minutes. This policy type uses machine learning and predefined thresholds to detect deviations from baseline activity, making it the correct choice for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Session policy

    Why it's wrong here

    Session policies apply real-time controls, not download thresholds.

  • App discovery policy

    Why it's wrong here

    App discovery policies identify shadow IT apps.

  • Anomaly detection policy

    Why this is correct

    Anomaly detection policies detect unusual file download activity.

  • OAuth app policy

    Why it's wrong here

    OAuth app policies manage third-party app permissions.

About these practice questions

This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on MS-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Defender for Cloud Apps. You need to generate alerts when a user downloads a large number of files from Microsoft SharePoint Online in a short period. What should you create?

easy
  • A.App Discovery policy
  • B.Activity policy
  • C.Anomaly Detection policy
  • D.Cloud Discovery policy

Why B: Activity policies in Defender for Cloud Apps allow you to create custom rules to detect specific activities like mass download. Option A (App Discovery policy) is used to discover apps in use in your organization. Option C (Anomaly Detection policy) is for pre-built anomalies. Option D (Cloud Discovery policy) is for shadow IT.

Variation 2. Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that alerts when a user downloads more than 10 files from SharePoint Online within 10 minutes. This activity should be considered anomalous. Which type of policy should you create?

easy
  • A.Cloud Discovery policy
  • B.Activity policy
  • C.Session policy
  • D.App discovery policy

Why B: Activity policies in Defender for Cloud Apps can detect anomalous activities based on thresholds, such as multiple file downloads. Option A is wrong because Cloud Discovery policies are used to discover cloud app usage (shadow IT). Option C is wrong because Session policies control sessions in real-time, not alert on historical activity. Option D is wrong because App discovery policies are used to discover shadow IT applications.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.