SC-100 Practice Question: Design security operations, identity, and compliance capabilities
A company uses Microsoft Defender for Cloud Apps to discover and control cloud apps. They want to receive alerts when a user accesses a sanctioned app from an unusual location. Which feature should they configure?
⚠ Common exam trap
Many exam-takers confuse anomaly detection policies with session policies, assuming that location-based alerts are enforced via real-time session controls, but session policies only act on traffic after access is granted, whereas anomaly detection policies are the correct detection mechanism for unusual location access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anomaly detection policies
Anomaly detection policies in Microsoft Defender for Cloud Apps are specifically designed to identify behavioral deviations, such as a user accessing a sanctioned app from an unusual geographic location. These policies leverage machine learning to establish a baseline of normal user activity and trigger alerts when access patterns deviate from that baseline, enabling detection of potential account compromise or insider threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Session policies
Why it's wrong here
Session policies in Microsoft Defender for Cloud Apps are conditional access controls that evaluate risk at sign-in and enforce real-time restrictions, such as blocking or limiting a session, based on the user's current context. They do not generate alerts for discovered anomalies like unusual geographic logins; instead, they are reactive mechanisms that mitigate access during the session itself, not proactive detectors of behavioral irregularities.
- ✗
File policies
Why it's wrong here
File policies are designed to monitor and enforce governance on cloud file sharing, such as detecting sensitive data exposure, external sharing, or malware propagation. They operate on file attributes and content, not on user location or authentication patterns, so they are ill-suited for alerting on an impossible travel or geolocation anomaly that would stem from a compromised account rather than a file event.
- ✓
Anomaly detection policies
Why this is correct
Anomaly detection policies in Defender for Cloud Apps use behavioral analytics and machine learning to baseline normal user activities and trigger alerts for deviations, including impossible travel, unfamiliar sign-in properties, and multiple failed sign-ins. These policies are specifically tailored to identify suspicious location-based behavior, such as sign-ins from geographically distant locations in a short time span, making them the correct choice for alerting on unusual user location patterns.
- ✗
App discovery policies
Why it's wrong here
App discovery policies are focused on identifying and cataloging shadow IT by analyzing cloud app usage, user engagement, and risk scores of various applications. They do not evaluate user behavior or location anomalies; rather, they provide visibility into which applications are being used across the organization and whether those apps pose compliance or security risks, leaving user-centric activity detection to other policy types.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.