Courseiva

SC-200 Manage a security operations environment Practice Question

You are configuring Microsoft Defender for Cloud Apps. You need to create a policy that alerts when a user downloads more than 100 files in 10 minutes from SharePoint. Which policy type should you use?

⚠ Common exam trap

It's easy for candidates to confuse 'Anomaly detection policy' (which uses machine learning for behavioral baselines) with 'Activity policy' (which uses explicit thresholds), leading them to select Option A for any threshold-based alert.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Activity policy

An Activity policy in Microsoft Defender for Cloud Apps monitors specific user activities (e.g., file downloads) and can trigger alerts based on thresholds like 'more than 100 downloads in 10 minutes'. This policy type is designed for granular, behavior-based detection of suspicious actions, making it the correct choice for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Anomaly detection policy

    Why it's wrong here

    Anomaly detection policies in Defender for Cloud Apps rely on built-in machine learning models that establish a baseline of each user's normal behavior and generate alerts when deviations exceed learned patterns. You cannot specify a hard-coded numeric threshold for specific actions such as 'more than 10 downloads in 5 minutes'; detection thresholds are dynamically adjusted by the ML engine. Therefore, an anomaly policy is not the right choice for defining a custom, fixed condition.

  • ✓

    Activity policy

    Why this is correct

    An activity policy is designed specifically to monitor user sign-in and app activity events, and it allows you to define custom behavioral conditions using filters, thresholds, and time windows. For example, you can create a policy that alerts when a user performs more than N file downloads within a set number of minutes, then automatically respond by suspending the user or requiring re-authentication. This matches the requirement for a custom threshold on download volume.

  • ✗

    File policy

    Why it's wrong here

    File policies evaluate attributes of files that have been shared or stored in connected cloud apps, such as the file name, owner, sharing level, and content classification, but they do not track the event count of downloads. Download volume is an activity metric rather than a file metadata property, so a file policy cannot alert on 'number of times a file was downloaded' in a time window. Thus it is incorrect for this scenario.

  • ✗

    Cloud discovery policy

    Why it's wrong here

    Cloud discovery policies analyze Shadow IT by inspecting network traffic logs to identify which unapproved cloud applications are being used throughout the organization. They do not monitor the activity events of individual users inside a single app like Microsoft Defender for Cloud Apps connected apps. Since the question is about user downloads within an app, a cloud discovery policy is not applicable.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.