Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization is using Microsoft Defender for Cloud Apps to protect cloud applications. The security team wants to be alerted when a user shares a sensitive file with an external user. What should you configure?

⚠ Common exam trap

Candidates often confuse activity policies (which monitor user actions) with file policies (which monitor file attributes and sharing permissions), leading them to choose Option A when the question explicitly mentions 'shares a sensitive file'—a file-centric event requiring content and sharing context.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

File policy

File policies in Microsoft Defender for Cloud Apps are specifically designed to monitor and respond to events involving files stored in connected cloud apps, such as when a sensitive file is shared with an external user. You can configure a file policy with a filter for 'External' sharing and apply a content inspection rule to detect sensitive information types, triggering an alert when the condition is met.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Activity policy

    Why it's wrong here

    Activity policies in Defender for Cloud Apps monitor user-driven events such as sign-ins, logon failures, downloads, and deletions across connected cloud apps. They can be configured to trigger on specific actions, but they operate at the activity level and do not natively parse file metadata, sharing permissions, or content the way file policies do. While an activity policy could capture an event like 'sharing a file,' it cannot enforce granular conditions on file attributes or collaborators, making it the wrong tool for comprehensive file-sharing monitoring.

  • ✗

    App discovery policy

    Why it's wrong here

    App discovery policies analyze network traffic logs to identify shadow IT and assess the risk of unsanctioned cloud applications. They examine features such as app catalog categories, risk scores, and usage patterns, but they do not monitor file content, sharing links, or permissions within already-connected applications. Since the organization needs to monitor file sharing in existing cloud apps, an app discovery policy is irrelevant because it focuses on discovering and governing new apps rather than inspecting files in known apps.

  • ✗

    Anomaly detection policy

    Why it's wrong here

    Anomaly detection policies rely on machine learning to identify unusual behavioral patterns such as impossible travel, mass download, or ransomware-like activity. They are probabilistic and adaptive, meaning they prioritize deviations from a baseline over specific, deterministic rules about file sharing. You cannot use an anomaly detection policy to define exact conditions like 'file shared externally' or 'file contains credit card numbers' because it is not designed for rule-based, file-centric enforcement, making it unsuitable for this requirement.

  • ✓

    File policy

    Why this is correct

    File policies are purpose-built in Defender for Cloud Apps to monitor and govern files stored in connected cloud apps such as SharePoint, OneDrive, Box, and Google Drive. They evaluate conditions on file metadata, sharing permissions, file name, and content inspection, and can trigger alerts or automatic actions like quarantine or revoking access. This allows you to create a policy that specifically detects files shared with external users, thereby directly addressing the requirement to monitor file sharing.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.