MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Cloud Apps. You need to generate alerts when a user downloads a large number of files from Microsoft SharePoint Online in a short period. What should you create?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Activity policy
Activity policies in Defender for Cloud Apps allow you to create custom rules to detect specific activities like mass download. Option A (App Discovery policy) is used to discover apps in use in your organization. Option C (Anomaly Detection policy) is for pre-built anomalies. Option D (Cloud Discovery policy) is for shadow IT.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
App Discovery policy
Why it's wrong here
App Discovery policies are designed to monitor and assess the cloud apps that are used in your organization, focusing on the app catalog score, risk, and usage. They help identify shadow IT by reviewing discovered apps, but they do not inspect the specific user actions that occur inside those apps, such as downloading files. Therefore, an App Discovery policy would not be able to alert on mass downloads.
- ✓
Activity policy
Why this is correct
An Activity policy is the correct choice because it gives you full control to create a conditional rule that matches a specific activity, such as downloading a file, and then combines it with parameters like the user, device, IP address, or even a repeated-activity threshold. You can set the policy to trigger when a user performs more than a defined number of downloads within a short period, which directly detects mass download behavior. This is the standard mechanism in Defender for Cloud Apps for defining custom, business-specific activity monitoring.
- ✗
Anomaly Detection policy
Why it's wrong here
Anomaly Detection policies in Defender for Cloud Apps rely on prebuilt machine learning behavioral models that look for unusual activity such as impossible travel or ransomware activity. They do not allow you to define a custom rule with specific filters and thresholds, such as a particular number of file downloads within a time window. To detect a mass download scenario, you need a policy that can be explicitly configured with those criteria.
- ✗
Cloud Discovery policy
Why it's wrong here
Cloud Discovery policies operate on the results of the Cloud Discovery feature, which analyzes network traffic logs to identify what cloud apps are being used. These policies trigger alerts when new or high-risk apps are discovered, or when the volume of discovered traffic changes, but they do not monitor the file-level activities of users within already-sanctioned apps. As a result, they cannot be used to detect a user conducting mass downloads.
Go deeper
Related to this question
Learn chapter
OneDrive Sharing Policies and External Access
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
SharePoint Online
SharePoint Online is a cloud-based collaboration platform from Microsoft that lets teams create, store, organize, and share content securely from anywhere.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.