Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Cloud Apps to monitor SaaS application usage. You need to generate an alert when a user performs more than 50 failed login attempts in 10 minutes, and the alert must be based on a built-in anomaly detection policy. What should you do?

⚠ Common exam trap

Watch out — candidates often confuse the purpose of session policies (which control real-time access) with anomaly detection policies (which detect behavioral patterns), leading them to incorrectly select Option B, or they assume a custom policy is always required (Option C) when a built-in policy already exists for this exact scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the 'Multiple failed login attempts' anomaly detection policy in Defender for Cloud Apps.

Microsoft Defender for Cloud Apps includes a built-in anomaly detection policy named 'Multiple failed login attempts' that specifically monitors for a high volume of failed logins from a single user within a short time window. This policy is enabled by default and can be customized to trigger alerts when the threshold (e.g., more than 50 failed attempts in 10 minutes) is exceeded, without requiring any additional configuration or custom policy creation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a data loss prevention (DLP) policy in Microsoft Purview that triggers on failed logins.

    Why it's wrong here

    Microsoft Purview DLP policies inspect content to protect sensitive data based on information types, labels, and file context; they are triggered by data exfiltration or sharing scenarios, not by authentication events. A failed login attempt occurs in the Entra ID/identity plane and is not content-bearing data, so DLP cannot key off a login failure count or condition. Thus this approach is conceptually invalid for surfacing anomaly alerts.

  • ✗

    Deploy a session policy in Defender for Cloud Apps that blocks after 50 failed logins.

    Why it's wrong here

    A Defender for Cloud Apps session policy is a real-time conditional access control that applies actions such as block or restrict at the moment a user accesses a SaaS app, typically via Microsoft Entra Conditional Access app control. It does not create detection alerts, and defining a threshold like 50 failed logins would require session-based logic that isn't designed for aggregating historical sign-in failures and raising an investigative alert. Anomaly detection policies are the alerting mechanism for such patterns.

  • ✗

    Configure an app connector for each SaaS app and then create a custom activity policy.

    Why it's wrong here

    Configuring app connectors adds API-level visibility into SaaS app activities but is not a prerequisite for the built-in anomaly detection templates, which use telemetry already processed by Defender for Cloud Apps. Furthermore, a custom activity policy is intended to match explicit, user-defined activities (e.g., a specific operation on a specific file) and will not perform behavioral baselining. Consequently, this option both misses the actual detection mechanism and introduces an unnecessary dependency.

  • ✓

    Enable the 'Multiple failed login attempts' anomaly detection policy in Defender for Cloud Apps.

    Why this is correct

    The 'Multiple failed login attempts' policy is a built-in anomaly detection policy in Defender for Cloud Apps that uses machine learning/UEBA to establish a per-user or per-tenant baseline and then flags abnormal spikes in failed sign-ins. Enabling this template automatically generates alerts when the anomaly is detected, and you can tune sensitivity and notification recipients. This is the correct, native way to meet the requirement without building custom activity rules or DLP policies.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization has Microsoft Defender for Cloud Apps enabled. You need to generate an alert when a user downloads more than 100 files from SharePoint in one hour. What should you create?

easy
  • A.A data loss prevention (DLP) policy in Microsoft Purview.
  • B.A custom alert in Microsoft Sentinel using the CloudAppEvents table.
  • C.An app governance policy in Microsoft Defender for Cloud Apps.
  • ✓ D.An anomaly detection policy in Microsoft Defender for Cloud Apps.

Why D: An anomaly detection policy in Microsoft Defender for Cloud Apps is designed to detect unusual user behavior, such as mass file downloads, by establishing a baseline and triggering alerts when activity deviates from the norm. This policy type specifically supports the scenario of detecting a user downloading more than 100 files from SharePoint in one hour, as it can be configured with custom thresholds for file download activity.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.