Courseiva

SC-200 Respond to security incidents Practice Question

You are responding to a data exfiltration incident involving a user who copied sensitive files to a personal cloud storage service. The files were accessed from the user's managed device. Which Microsoft Defender for Cloud Apps activity policy should you create to detect similar future incidents?

⚠ Common exam trap

Many candidates confuse 'file policy' (which governs sharing and permissions) with 'activity policy' (which governs actions like uploads), leading them to incorrectly select Option C, which detects shared files rather than the act of uploading.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An activity policy that detects uploads to personal cloud storage services.

The incident involves a user copying sensitive files to a personal cloud storage service from a managed device. An activity policy in Microsoft Defender for Cloud Apps can be configured to detect specific activities, such as uploads to personal cloud storage services (e.g., Dropbox, Google Drive), by monitoring the 'Upload' event for recognized cloud apps. This directly addresses the detection of similar future incidents by alerting on the exact action (upload) to the specific service category (personal storage).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An anomaly detection policy that flags impossible travel.

    Why it's wrong here

    An anomaly detection policy in Microsoft Defender for Cloud Apps uses machine learning to detect behavioral anomalies like impossible travel, which indicates a compromised account. However, it does not target specific actions such as uploading files to personal cloud storage; rather, it flags deviations from a user's normal sign-in pattern. While this could be correlated with exfiltration, it is not a direct detection control for the specific upload activity described in the incident.

  • ✓

    An activity policy that detects uploads to personal cloud storage services.

    Why this is correct

    An activity policy in Microsoft Defender for Cloud Apps is designed to monitor specific actions, such as file uploads, across cloud apps. You can configure policy filters based on app (e.g., personal cloud storage services) and the activity type (e.g., upload). This directly matches the incident by triggering an alert when a user uploads a file to a non-corporate cloud service, making it the correct response control.

  • ✗

    A file policy that detects files shared with external users.

    Why it's wrong here

    A file policy in Microsoft Defender for Cloud Apps inspects files that are already stored in connected cloud apps, focusing on their sharing permissions, metadata, or content. It is used to detect exposed or sensitive files, such as those shared with external users, but it does not monitor the act of uploading a file to a personal cloud service. Therefore, it would not fire on the upload action itself, only on resulting file exposure if the file appears in a synchronized or connected app.

  • ✗

    An app discovery policy that identifies new cloud apps used in the organization.

    Why it's wrong here

    An app discovery policy analyzes traffic logs to identify which cloud apps are being used in the organization, often via a log collector or proxy integration. It is useful for shadow IT detection by discovering new or unsanctioned apps, but it does not provide visibility into the specific activities within those apps. Thus, while it might show that a personal cloud storage app is in use, it cannot detect a specific upload event, so it would not directly address the data exfiltration incident.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.