MS-102 Activity policy Practice Question
Your organization uses Microsoft Defender for Cloud Apps. You need to generate alerts when a user downloads more than 100 files from SharePoint Online within 10 minutes. What should you configure?
⚠ Common exam trap
MS-102 often tests the confusion between activity policies (monitor user actions) and session policies (control access in real-time); candidates may pick session policy thinking it can alert on download volume, but session policies are for inline enforcement, not threshold-based alerting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an activity policy
Activity policies in Microsoft Defender for Cloud Apps are designed to monitor user activities across connected apps and generate alerts when specific conditions are met, such as a user downloading more than 100 files from SharePoint Online within 10 minutes. This is a classic anomaly detection scenario that activity policies handle natively. The other policy types serve different purposes: app discovery for shadow IT, session policies for conditional access, and OAuth app policies for app permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an activity policy
Why this is correct
Activity policies in Microsoft Defender for Cloud Apps evaluate user actions against thresholds and generate alerts or governance actions. Configuring one with a file-download criterion and a 100-file count within a 10-minute window detects the mass-download behaviour.
- ✗
Create an app discovery policy
Why it's wrong here
An app discovery policy analyses shadow-IT usage from firewall and proxy logs, so it cannot read SharePoint Online file-download events or count them per user within a ten-minute window. It is tempting because discovery policies do identify unsanctioned cloud apps, which would be right when cataloguing unknown SaaS usage rather than alerting on sanctioned SharePoint activity.
- ✗
Create a session policy
Why it's wrong here
Session policies apply inline DLP and real-time controls to active user sessions, not threshold-based alerting on file downloads. Activity policies evaluate user actions against filters such as download volume and trigger alerts; this scenario requires exactly that. Session policy is the right choice when you must block or protect content during a live session.
- ✗
Create an OAuth app policy
Why it's wrong here
OAuth app policies govern permission grants and consent for connected applications, not user download volumes. They suit scenarios where a risky third-party app requests excessive scopes or an admin wants to revoke an app's access.
Go deeper
Related to this question
Learn chapter
Microsoft Defender for Cloud Apps Administration
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
SharePoint Online
SharePoint Online is a cloud-based collaboration platform from Microsoft that lets teams create, store, organize, and share content securely from anywhere.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.