Courseiva

MS-102 Activity policy Practice Question

Your organization uses Microsoft Defender for Cloud Apps. You need to generate alerts when a user downloads more than 100 files from SharePoint Online within 10 minutes. What should you configure?

⚠ Common exam trap

MS-102 often tests the confusion between activity policies (monitor user actions) and session policies (control access in real-time); candidates may pick session policy thinking it can alert on download volume, but session policies are for inline enforcement, not threshold-based alerting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an activity policy

Activity policies in Microsoft Defender for Cloud Apps are designed to monitor user activities across connected apps and generate alerts when specific conditions are met, such as a user downloading more than 100 files from SharePoint Online within 10 minutes. This is a classic anomaly detection scenario that activity policies handle natively. The other policy types serve different purposes: app discovery for shadow IT, session policies for conditional access, and OAuth app policies for app permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an activity policy

    Why this is correct

    Activity policies in Microsoft Defender for Cloud Apps evaluate user actions against thresholds and generate alerts or governance actions. Configuring one with a file-download criterion and a 100-file count within a 10-minute window detects the mass-download behaviour.

  • ✗

    Create an app discovery policy

    Why it's wrong here

    An app discovery policy analyses shadow-IT usage from firewall and proxy logs, so it cannot read SharePoint Online file-download events or count them per user within a ten-minute window. It is tempting because discovery policies do identify unsanctioned cloud apps, which would be right when cataloguing unknown SaaS usage rather than alerting on sanctioned SharePoint activity.

  • ✗

    Create a session policy

    Why it's wrong here

    Session policies apply inline DLP and real-time controls to active user sessions, not threshold-based alerting on file downloads. Activity policies evaluate user actions against filters such as download volume and trigger alerts; this scenario requires exactly that. Session policy is the right choice when you must block or protect content during a live session.

  • ✗

    Create an OAuth app policy

    Why it's wrong here

    OAuth app policies govern permission grants and consent for connected applications, not user download volumes. They suit scenarios where a risky third-party app requests excessive scopes or an admin wants to revoke an app's access.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.