Alert on Anonymous IP Access — Activity Policy in Defender for Cloud Apps
Your organization has Microsoft Defender for Cloud Apps (MDA) connected to Microsoft Sentinel. The SOC team wants to receive alerts when a user accesses a sanctioned cloud app from an anonymous IP address. What should you configure?
Quick Answer
The correct answer is to create an activity policy in Defender for Cloud Apps and connect it to Sentinel. This is because an activity policy monitors user behavior events, such as logging into a sanctioned cloud app from an anonymous IP address, and can trigger alerts based on those specific actions. Unlike file policies, which only scan for data-level risks like sharing or malware, or session policies, which control real-time access without generating historical alerts, the activity policy is designed precisely for tracking user access anomalies. On the SC-200 exam, this question tests your understanding of how Defender for Cloud Apps policies map to different threat scenarios—a common trap is confusing file policies with activity policies. Remember the memory tip: "Activity for access, File for content"—if the alert is about who accessed what from where, it’s always an activity policy.
⚠ Common exam trap
Candidates often confuse file policies with activity policies, assuming any policy in Defender for Cloud Apps can detect access events, but only activity policies are designed to monitor user sign-in and access behaviors against IP-based conditions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an activity policy in Defender for Cloud Apps and connect it to Sentinel.
An activity policy in Defender for Cloud Apps can be configured to trigger alerts on specific user activities, such as accessing a sanctioned app from an anonymous IP address. This policy can then be connected to Microsoft Sentinel via the Defender for Cloud Apps data connector, which ingests alerts as incidents for SOC review. File policies (A) focus on file-level actions like sharing or malware detection, not user access events, while session policies (D) control real-time access but do not generate alerts for historical or post-access monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a file policy in Defender for Cloud Apps.
Why it's wrong here
File policies are designed to protect sensitive data, not detect anonymous IP access.
- ✓
Create an activity policy in Defender for Cloud Apps and connect it to Sentinel.
Why this is correct
Activity policies can detect specific behaviors like anonymous IP access and send alerts to Sentinel.
- ✗
Enable the Defender for Cloud Apps connector in Sentinel without additional configuration.
Why it's wrong here
The connector ingests alerts, but you need a policy in Defender for Cloud Apps to generate the specific alert.
- ✗
Create a session policy in Defender for Cloud Apps.
Why it's wrong here
Session policies monitor and control activities in real-time, but they do not generate alerts in Sentinel directly.
Go deeper
Related to this question
About these practice questions
One of 209 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are configuring Microsoft Defender for Cloud Apps. You need to create a policy that alerts when a user downloads more than 100 files in 10 minutes from SharePoint. Which policy type should you use?
hard- A.Anomaly detection policy
- ✓ B.Activity policy
- C.File policy
- D.Cloud discovery policy
Why B: An Activity policy in Microsoft Defender for Cloud Apps monitors specific user activities (e.g., file downloads) and can trigger alerts based on thresholds like 'more than 100 downloads in 10 minutes'. This policy type is designed for granular, behavior-based detection of suspicious actions, making it the correct choice for this scenario.
Variation 2. You are managing Microsoft Defender for Cloud Apps. You discover that a user is downloading large amounts of data from a sanctioned cloud app. You need to automatically suspend the user's access when the download exceeds 5 GB in 10 minutes. What should you create?
medium- ✓ A.An anomaly detection policy with a mass download detection template.
- B.A session policy to block downloads.
- C.An app connector for the cloud app.
- D.A data loss prevention (DLP) policy in Microsoft Purview.
Why A: An anomaly detection policy in Microsoft Defender for Cloud Apps can detect unusual user behavior, such as mass file downloads, using predefined templates like 'Mass download by a single user'. This policy can be configured to trigger automatic governance actions, including suspending the user, when the download exceeds a threshold like 5 GB in 10 minutes. It directly addresses the need to automatically suspend access based on volume and time.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.