Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Cloud Apps. You need to generate alerts when a user downloads a large number of files from Microsoft SharePoint Online in a short period. What should you create?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Activity policy

Activity policies in Defender for Cloud Apps allow you to create custom rules to detect specific activities like mass download. Option A (App Discovery policy) is used to discover apps in use in your organization. Option C (Anomaly Detection policy) is for pre-built anomalies. Option D (Cloud Discovery policy) is for shadow IT.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    App Discovery policy

    Why it's wrong here

    App Discovery policies are designed to monitor and assess the cloud apps that are used in your organization, focusing on the app catalog score, risk, and usage. They help identify shadow IT by reviewing discovered apps, but they do not inspect the specific user actions that occur inside those apps, such as downloading files. Therefore, an App Discovery policy would not be able to alert on mass downloads.

  • ✓

    Activity policy

    Why this is correct

    An Activity policy is the correct choice because it gives you full control to create a conditional rule that matches a specific activity, such as downloading a file, and then combines it with parameters like the user, device, IP address, or even a repeated-activity threshold. You can set the policy to trigger when a user performs more than a defined number of downloads within a short period, which directly detects mass download behavior. This is the standard mechanism in Defender for Cloud Apps for defining custom, business-specific activity monitoring.

  • ✗

    Anomaly Detection policy

    Why it's wrong here

    Anomaly Detection policies in Defender for Cloud Apps rely on prebuilt machine learning behavioral models that look for unusual activity such as impossible travel or ransomware activity. They do not allow you to define a custom rule with specific filters and thresholds, such as a particular number of file downloads within a time window. To detect a mass download scenario, you need a policy that can be explicitly configured with those criteria.

  • ✗

    Cloud Discovery policy

    Why it's wrong here

    Cloud Discovery policies operate on the results of the Cloud Discovery feature, which analyzes network traffic logs to identify what cloud apps are being used. These policies trigger alerts when new or high-risk apps are discovered, or when the volume of discovered traffic changes, but they do not monitor the file-level activities of users within already-sanctioned apps. As a result, they cannot be used to detect a user conducting mass downloads.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.