SC-200 Manage a security operations environment Practice Question
Your organization has Microsoft Defender for Cloud Apps enabled. You need to generate an alert when a user downloads more than 100 files from SharePoint in one hour. What should you create?
⚠ Common exam trap
Watch out — candidates often confuse anomaly detection policies with DLP policies, assuming that any data exfiltration scenario must be handled by DLP, but DLP policies in Purview are content-based, not volume-based, making anomaly detection the correct choice for this behavioral threshold scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An anomaly detection policy in Microsoft Defender for Cloud Apps.
An anomaly detection policy in Microsoft Defender for Cloud Apps is designed to detect unusual user behavior, such as mass file downloads, by establishing a baseline and triggering alerts when activity deviates from the norm. This policy type specifically supports the scenario of detecting a user downloading more than 100 files from SharePoint in one hour, as it can be configured with custom thresholds for file download activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A data loss prevention (DLP) policy in Microsoft Purview.
Why it's wrong here
A Microsoft Purview DLP policy is designed to inspect content for sensitive information (e.g., credit card numbers, PII) and apply protection actions such as blocking or encrypting that content. It does not model or monitor baseline user behavior, so it cannot detect an anomalous spike in activity volume—that requires behavioral analytics, not content inspection.
- ✗
A custom alert in Microsoft Sentinel using the CloudAppEvents table.
Why it's wrong here
While you can ingest the CloudAppEvents table into Microsoft Sentinel and write a KQL query to alert on high activity counts, this is a custom analytics rule external to the Defender for Cloud Apps console. The question specifically asks for a policy *in* Microsoft Defender for Cloud Apps, and Sentinel is a separate SIEM platform, so a custom Sentinel alert is not the in-platform answer.
- ✗
An app governance policy in Microsoft Defender for Cloud Apps.
Why it's wrong here
App governance policies in Defender for Cloud Apps are focused on OAuth-enabled apps—they assess app permissions, consent grants, and app-level risky behaviors like over-privileged scopes or use by compromised accounts. They do not analyze user activity volumes or establish per-user baselines, so they are not relevant for detecting an unusually high number of user activities.
- ✓
An anomaly detection policy in Microsoft Defender for Cloud Apps.
Why this is correct
An anomaly detection policy in Microsoft Defender for Cloud Apps uses user and entity behavior analytics (UEBA) to build a per-user baseline of normal activity. When a user's activity volume significantly deviates from that baseline—for example, an unusually high number of file downloads or sign-in events—the policy generates an alert, making it the correct native mechanism for this scenario.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.