SC-200 Manage a security operations environment Practice Question
You are configuring Microsoft Defender for Cloud Apps. You need to create a policy that alerts when a user downloads more than 100 files in 10 minutes from SharePoint. Which policy type should you use?
⚠ Common exam trap
It's easy for candidates to confuse 'Anomaly detection policy' (which uses machine learning for behavioral baselines) with 'Activity policy' (which uses explicit thresholds), leading them to select Option A for any threshold-based alert.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Activity policy
An Activity policy in Microsoft Defender for Cloud Apps monitors specific user activities (e.g., file downloads) and can trigger alerts based on thresholds like 'more than 100 downloads in 10 minutes'. This policy type is designed for granular, behavior-based detection of suspicious actions, making it the correct choice for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Anomaly detection policy
Why it's wrong here
Anomaly detection policies in Defender for Cloud Apps rely on built-in machine learning models that establish a baseline of each user's normal behavior and generate alerts when deviations exceed learned patterns. You cannot specify a hard-coded numeric threshold for specific actions such as 'more than 10 downloads in 5 minutes'; detection thresholds are dynamically adjusted by the ML engine. Therefore, an anomaly policy is not the right choice for defining a custom, fixed condition.
- ✓
Activity policy
Why this is correct
An activity policy is designed specifically to monitor user sign-in and app activity events, and it allows you to define custom behavioral conditions using filters, thresholds, and time windows. For example, you can create a policy that alerts when a user performs more than N file downloads within a set number of minutes, then automatically respond by suspending the user or requiring re-authentication. This matches the requirement for a custom threshold on download volume.
- ✗
File policy
Why it's wrong here
File policies evaluate attributes of files that have been shared or stored in connected cloud apps, such as the file name, owner, sharing level, and content classification, but they do not track the event count of downloads. Download volume is an activity metric rather than a file metadata property, so a file policy cannot alert on 'number of times a file was downloaded' in a time window. Thus it is incorrect for this scenario.
- ✗
Cloud discovery policy
Why it's wrong here
Cloud discovery policies analyze Shadow IT by inspecting network traffic logs to identify which unapproved cloud applications are being used throughout the organization. They do not monitor the activity events of individual users inside a single app like Microsoft Defender for Cloud Apps connected apps. Since the question is about user downloads within an app, a cloud discovery policy is not applicable.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.