Courseiva

SC-200 Manage a security operations environment Practice Question

You are a SOC analyst investigating an incident where a user's credentials were used to access a sensitive SharePoint site from an unusual location. Microsoft Defender for Cloud Apps detected the activity as a suspicious sign-in. You need to create a detection rule that alerts whenever a user accesses SharePoint from a location not in the allowed list. What type of rule should you create in Microsoft Defender for Cloud Apps?

⚠ Common exam trap

It's easy for candidates to confuse 'Anomaly detection policy' (which is built-in and uses ML) with the ability to create custom location-based alerts, but only Activity policies allow you to define explicit conditions like 'not in allowed list'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Activity policy.

An Activity policy in Microsoft Defender for Cloud Apps allows you to create custom rules that trigger alerts based on specific user activities, such as accessing SharePoint from a location not in the allowed list. This policy type evaluates each activity against defined conditions (e.g., IP address ranges, geolocation) and can generate alerts or take automated actions. It is the correct choice because it directly matches the requirement to detect a specific access pattern (location-based anomaly) rather than broad behavioral patterns.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    App discovery policy.

    Why it's wrong here

    App discovery policy identifies shadow IT by analyzing traffic logs to reveal which cloud apps users are accessing, rather than evaluating specific sign-in conditions. It focuses on cataloging usage, not on detecting past events based on location criteria. Therefore, an app discovery policy would not generate an alert for a user activity matching a defined location, making it incorrect for this incident investigation.

  • ✗

    Session policy.

    Why it's wrong here

    Session policy is a real-time access control mechanism that enforces constraints, such as blocking downloads or requiring MFA, when a user attempts to access a cloud app. It does not assess historical activity or trigger alerts for past events, because policy evaluation happens during the session itself. Consequently, a session policy cannot be used to investigate or identify an incident that has already occurred.

  • ✓

    Activity policy.

    Why this is correct

    Activity policy in Microsoft Defender for Cloud Apps allows you to define custom rules based on specific activities, including conditions like location, to trigger alerts. You can set thresholds and filters to detect exactly the kind of user activity in question, such as a sign-in from a particular geographic region. This makes it the appropriate policy type for investigating an incident where a user’s location is a defining factor of the suspicious behavior.

  • ✗

    Anomaly detection policy.

    Why it's wrong here

    Anomaly detection policy uses machine learning to build behavior profiles for users and peers, alerting on deviations from those baselines, like impossible travel or unusual sign-in patterns. It does not rely on static location lists, so you cannot specify a particular country or IP range to match against. Because the incident requires a defined location condition, this policy type would not reliably trigger on the exact scenario.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.