Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization has Microsoft Defender for Cloud Apps and Microsoft Sentinel integrated. The security team wants to receive alerts when a user's activity from an anonymous IP address exceeds a certain risk score. What should you configure in Defender for Cloud Apps?

⚠ Common exam trap

Test-takers frequently confuse anomaly detection policies (which detect behavioral anomalies) with activity policies (which allow explicit condition-based filtering), leading them to select Option A incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Activity policy

Activity policies in Microsoft Defender for Cloud Apps allow you to monitor and respond to specific user activities based on conditions such as IP address categories (e.g., anonymous proxy) and risk scores. This policy type can trigger alerts when a user's activity from an anonymous IP address exceeds a defined risk score threshold, meeting the security team's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Anomaly detection policy

    Why it's wrong here

    Anomaly detection policies in Defender for Cloud Apps rely on machine learning to create a behavioral baseline for users, then flag deviations such as impossible travel, mass download, or credential theft related to specific anomalous patterns. They are not designed to catch every action from an anonymous IP as a static, deterministic condition, because their logic is based on statistical outliers rather than explicit filters like IP category equals Anonymous. To reliably alert on a user signing in from an anonymous IP, an activity policy is the appropriate construct.

  • ✗

    File policy

    Why it's wrong here

    File policies in Defender for Cloud Apps are focused on content inspection and monitoring of file access, sharing, and storage, such as finding externally shared sensitive documents or applying quarantines on SharePoint/OneDrive items. They evaluate file metadata and content, not the IP address category or sign-in context of the user performing an activity. Since the threat in this scenario is a login from an anonymous IP, that is an activity-level signal outside the scope of file-centric policies.

  • ✓

    Activity policy

    Why this is correct

    Activity policies are the correct choice because they allow you to define custom, rule-based conditions on tens of thousands of user operations, including sign-in events, admin actions, and file accesses. These policies support granular filters like IP category (including Anonymous), user risk level, and device tags, so you can trigger an immediate alert when a user logs in from an anonymous IP. Unlike anomaly detection, this is deterministic and provides precise, actionable results with low noise.

  • ✗

    App discovery policy

    Why it's wrong here

    App discovery policies are designed to identify and assess shadow IT by analyzing cloud discovery logs to report which apps users are accessing and the app risk scores. They focus on app-level metadata and aggregate usage patterns, not individual user sign-in events or the IP address category of a specific action. Therefore, they cannot be used to alert on a user accessing a service from an anonymous IP, making them inapplicable to this scenario.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.