MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that detects when a user signs in from an unknown IP address and then downloads a large number of files. Which THREE components should you configure?
⚠ Common exam trap
Many exam-takers confuse the IP address range category (Option A) as a required component for defining unknown IPs in an anomaly detection policy, when in fact the policy automatically uses the organization's configured IP ranges and does not require a separate category to be selected during policy creation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scope (users and groups)
The policy must be scoped to specific users or groups to ensure that the anomaly detection rule (unknown IP followed by mass download) applies only to the intended set of accounts. Without scoping, the policy would evaluate all users, which may generate excessive noise or miss targeted monitoring. In Microsoft Defender for Cloud Apps, the Scope (users and groups) setting is a required component when creating an anomaly detection policy to define which identities are monitored.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IP address range category
Why it's wrong here
IP address ranges in an anomaly detection policy are not a separate component; rather, they are integrated as a filter within the selected detection template. When configuring a policy like 'Impossible travel', you include known benign IP ranges (such as corporate public egress IPs or VPN addresses) as part of the template's conditions. This allows the policy to ignore activity from those trusted locations, but the IP range category itself is not a distinct configurable element of the policy structure.
- ✓
Scope (users and groups)
Why this is correct
The Scope (users and groups) component is a mandatory and correct part of an anomaly detection policy in Microsoft Defender for Cloud Apps. It defines the set of users or groups whose activity is monitored and evaluated against the detection template. For example, you can scope the policy to only your global administrators or a specific group of high-privilege users, which reduces false positives and focuses on the accounts that matter most. Without a defined scope, the policy cannot determine whose activities are subject to anomaly analysis.
- ✓
Anomaly detection policy template
Why this is correct
The anomaly detection policy template is a core component, embodying the detection logic used to identify suspicious activities. Defender for Cloud Apps provides templates such as 'Impossible travel', 'Activity from infrequent country', and 'Unusual multiple sign-in attempts', each powered by machine learning to establish a per-user baseline and flag deviations from that baseline. The template dictates the specific behavioral anomalies that will trigger an alert, making it essential to the policy's function. Selecting the correct template is how you specify the type of threat you are trying to detect.
- ✗
Session policy
Why it's wrong here
Session policies are incorrect here because they serve a different purpose: they enforce real-time, conditional access controls on user sessions, such as blocking downloads, requiring multi-factor authentication, or restricting access to specific apps. In contrast, an anomaly detection policy works asynchronously, analyzing historical activity logs to identify past suspicious patterns. A session policy is an ex-ante control mechanism, whereas an anomaly detection policy is an ex-post detection mechanism. Therefore, session policies are not a component of anomaly detection policy configuration.
- ✓
Alert settings
Why this is correct
Alert settings are a correct and necessary component of an anomaly detection policy, as they determine how and where notifications are sent when an anomaly is triggered. This includes setting the alert severity level, email recipients, and integration with automation (e.g., Power Automate flows or external SIEM tools). You can also configure alert volume thresholds to suppress noise or escalate alerts to a security operations team. Without alert settings, the detection results would have no operational impact.
Go deeper
Related to this question
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.