Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Cloud Apps. You need to be alerted when a user accesses a cloud app from a risky IP address. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an anomaly detection policy with the 'Activity from risky IP address' template.

An anomaly detection policy can alert on activities from risky IP addresses. Option B is wrong because session policies control real-time access. Option C is wrong because file policies monitor data. Option D is wrong because access policies control access based on conditions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an anomaly detection policy with the 'Activity from risky IP address' template.

    Why this is correct

    The 'Activity from risky IP address' template is a built-in anomaly detection policy in Microsoft Defender for Cloud Apps that leverages Microsoft threat intelligence to identify IP addresses associated with malicious activity, such as anonymous proxies, Tor exit nodes, or known botnets. When a user performs an activity from one of these IPs, the policy generates an alert, giving security teams immediate visibility into the potentially compromised session. This is exactly the alerting capability needed in this scenario.

  • ✗

    Create a session policy to monitor risky IP addresses.

    Why it's wrong here

    A session policy in Defender for Cloud Apps is designed for real-time session control, such as blocking downloads, restricting access to specific apps, or prompting step-up authentication when certain conditions, including IP address, are met. While you can condition a session policy on an IP address, session policies enforce access restrictions rather than generate standalone alerts; they manage the session in the moment but do not notify your security team about the risky IP occurrence. For alerting on risky IP activity, you need an anomaly detection policy.

  • ✗

    Create a file policy to detect access from risky IPs.

    Why it's wrong here

    File policies in Defender for Cloud Apps are centered on file content and activities—for example, detecting when sensitive data is shared externally, when files are quarantined, or when mass downloads occur. They inspect file metadata and content, not the source IP address of the user session, so a file policy cannot be configured to detect access from a risky IP. The condition of a risky IP is outside the scope of file policy templates and conditions.

  • ✗

    Create an access policy to block risky IPs.

    Why it's wrong here

    An access policy, also known as a conditional access policy in Defender for Cloud Apps, can block or restrict a user's session based on attributes like IP address, device state, or user risk. Creating an access policy to block risky IPs will prevent the user from reaching the app, but it will not generate an alert unless you also configure a separate anomaly detection policy. Since the goal is to receive an alert, an access policy alone is insufficient.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MS-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Defender for Cloud Apps. You need to be alerted when a user accesses a cloud app from an anonymous IP address. Which type of policy should you create?

easy
  • A.Session policy
  • B.File policy
  • ✓ C.Activity policy
  • D.App discovery policy

Why C: An activity policy in Microsoft Defender for Cloud Apps can detect access from anonymous IP addresses by monitoring user activities. Option A is incorrect because a session policy controls user sessions in real-time but does not specifically alert on anonymous IP access. Option B is incorrect because a file policy focuses on monitoring and protecting files, not on access from anonymous IPs. Option D is incorrect because an app discovery policy is used to discover shadow IT and unsanctioned apps, not to alert on anonymous IP access.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.