MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Cloud Apps. You want to detect when a user accesses a sanctioned cloud app from an anonymous IP address. What should you configure?
⚠ Common exam trap
MS-102 often tests the difference between activity policies (detection/alerting on user actions) and session policies (real-time control of app sessions) — candidates pick session policy because 'anonymous IP' sounds like a blocking condition, but the question asks for detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an activity policy in Defender for Cloud Apps
An activity policy in Microsoft Defender for Cloud Apps is designed to monitor user activities and generate alerts based on conditions such as anonymous IP address usage. Since the requirement is to detect (not block) access from anonymous IPs, an activity policy with the 'Anonymous IP address' filter is the correct configuration. It leverages the built-in anonymous IP detection in Defender for Cloud Apps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure an app discovery policy
Why it's wrong here
App discovery policies govern unsanctioned app usage and risk scoring, not sign-in source attributes of sanctioned apps. It is tempting because discovery policies do surface risky cloud activity, and they would be correct for identifying shadow IT or unsanctioned apps in use across the tenant.
- ✗
Set up a session policy to block access from anonymous IPs
Why it's wrong here
Session policies apply conditional access controls during an active session, blocking or protecting downloads; they do not generate the detection alert requested. It is tempting because blocking anonymous IPs sounds like the desired outcome, and a session policy would be correct for real-time download control in a sanctioned app.
- ✗
Enable the cloud discovery shadow IT report
Why it's wrong here
The shadow IT report catalogues discovered apps and usage volumes; it does not evaluate sign-in source IPs against anonymous proxies. It is tempting because cloud discovery does highlight risky apps, and it would be correct for building an inventory of unsanctioned apps and their users.
- ✓
Create an activity policy in Defender for Cloud Apps
Why this is correct
Activity policies in Microsoft Defender for Cloud Apps evaluate user activity against filters such as anonymous IP proxy, generating alerts when a sanctioned app is accessed from an anonymising source. This matches the detection requirement precisely.
Go deeper
Related to this question
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.