Courseiva

SC-200 Manage a security operations environment Practice Question

You are responsible for Microsoft Defender for Cloud Apps. The security team reports that they are not receiving alerts for suspicious activities from a specific connected app (Salesforce). You verify that the app is connected and the log collection is working. What should you check next?

⚠ Common exam trap

Test-takers frequently assume connectivity and log collection guarantee alert generation, but they overlook that the anomaly detection policy is a separate toggle that must be explicitly enabled for each connected app.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure that the anomaly detection policy for Salesforce is enabled in Defender for Cloud Apps.

Since the app is connected and log collection is verified, the issue is likely that the anomaly detection policy for Salesforce is disabled. Defender for Cloud Apps uses built-in anomaly detection policies to generate alerts for suspicious activities; if the policy is turned off, no alerts will be raised even though data flows correctly. Enabling the policy ensures that behavioral baselines and threat detection are applied to the Salesforce logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Review the IP address ranges configured for the Salesforce app.

    Why it's wrong here

    Reviewing IP address ranges in the Salesforce app configuration only affects how Defender for Cloud Apps tags client locations, such as labeling a login as from your corporate headquarters or a risky region. These ranges are metadata for enrichment, not a condition that any anomaly detection policy evaluates, so adjusting them will never generate or suppress an alert for anomalous Salesforce activity. The alert you are investigating must originate from an enabled policy that monitors actual user and app behavior, not from static network address definitions.

  • ✓

    Ensure that the anomaly detection policy for Salesforce is enabled in Defender for Cloud Apps.

    Why this is correct

    You must explicitly enable an anomaly detection policy that targets Salesforce in Microsoft Defender for Cloud Apps because these policies are not automatically applied to every connected app. The 'Anomalous activity' policy, for example, can be customized per app family, and if Salesforce is not included or the policy is disabled, no alerts will be raised for unusual sign-ins, downloads, or admin actions in that tenant. Enabling the policy under Policies > Anomaly detection and confirming the Salesforce app is listed as a filter or data source is the direct prerequisite to receive the alert you are investigating.

  • ✗

    Check if the Salesforce app connector is properly configured in Microsoft Entra ID.

    Why it's wrong here

    The Salesforce app connector lives entirely in Microsoft Defender for Cloud Apps (or the Microsoft Defender XDR portal), not in Microsoft Entra ID; its purpose is to pull activity logs from Salesforce via the Salesforce API for cloud discovery and policy evaluation. While Entra ID handles identity and access for your workforce, it does not host third-party SaaS connectors or their settings, so checking it would be unrelated to why Salesforce anomaly alerts are missing. The connector must be configured in Defender for Cloud Apps itself, and if it were not connected, you would receive no Salesforce activity at all—a different symptom than an enabled policy not alerting.

  • ✗

    Verify that the Salesforce tenant is licensed for Microsoft Entra ID P2.

    Why it's wrong here

    Microsoft Entra ID P2 licensing provides premium identity protection features like user risk and conditional access, but it is not a prerequisite for Defender for Cloud Apps anomaly detection alerts. Defender for Cloud Apps is licensed through Microsoft 365 E5, E5 Security, standalone Defender for Cloud Apps, or included in some security bundles, and its anomaly detection policies operate independently of the identity tier you own. Verifying Entra ID P2 would be a red herring because a tenant with only P1 or even free Entra ID could still generate Salesforce alerts if the app connector and anomaly policy are properly configured.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.