Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

A company uses Microsoft Defender for Cloud Apps to discover and control cloud apps. They want to receive alerts when a user accesses a sanctioned app from an unusual location. Which feature should they configure?

⚠ Common exam trap

Many exam-takers confuse anomaly detection policies with session policies, assuming that location-based alerts are enforced via real-time session controls, but session policies only act on traffic after access is granted, whereas anomaly detection policies are the correct detection mechanism for unusual location access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Anomaly detection policies

Anomaly detection policies in Microsoft Defender for Cloud Apps are specifically designed to identify behavioral deviations, such as a user accessing a sanctioned app from an unusual geographic location. These policies leverage machine learning to establish a baseline of normal user activity and trigger alerts when access patterns deviate from that baseline, enabling detection of potential account compromise or insider threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Session policies

    Why it's wrong here

    Session policies in Microsoft Defender for Cloud Apps are conditional access controls that evaluate risk at sign-in and enforce real-time restrictions, such as blocking or limiting a session, based on the user's current context. They do not generate alerts for discovered anomalies like unusual geographic logins; instead, they are reactive mechanisms that mitigate access during the session itself, not proactive detectors of behavioral irregularities.

  • ✗

    File policies

    Why it's wrong here

    File policies are designed to monitor and enforce governance on cloud file sharing, such as detecting sensitive data exposure, external sharing, or malware propagation. They operate on file attributes and content, not on user location or authentication patterns, so they are ill-suited for alerting on an impossible travel or geolocation anomaly that would stem from a compromised account rather than a file event.

  • ✓

    Anomaly detection policies

    Why this is correct

    Anomaly detection policies in Defender for Cloud Apps use behavioral analytics and machine learning to baseline normal user activities and trigger alerts for deviations, including impossible travel, unfamiliar sign-in properties, and multiple failed sign-ins. These policies are specifically tailored to identify suspicious location-based behavior, such as sign-ins from geographically distant locations in a short time span, making them the correct choice for alerting on unusual user location patterns.

  • ✗

    App discovery policies

    Why it's wrong here

    App discovery policies are focused on identifying and cataloging shadow IT by analyzing cloud app usage, user engagement, and risk scores of various applications. They do not evaluate user behavior or location anomalies; rather, they provide visibility into which applications are being used across the organization and whether those apps pose compliance or security risks, leaving user-centric activity detection to other policy types.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.