SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that alerts when a user downloads more than 10 files from SharePoint in 5 minutes. What type of policy should you create?
⚠ Common exam trap
Candidates often confuse Activity policies with Anomaly detection policies, assuming any threshold-based alert is 'anomaly detection,' but Activity policies use explicit, static thresholds while Anomaly detection policies use dynamic, machine-learned baselines.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Activity policy
An Activity policy in Microsoft Defender for Cloud Apps is designed to monitor and respond to specific user activities, such as file downloads from SharePoint, based on predefined thresholds. By configuring the policy with a threshold of more than 10 downloads within 5 minutes, it triggers an alert when the activity exceeds this limit, enabling detection of potential data exfiltration or anomalous user behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Activity policy
Why this is correct
In Microsoft Defender for Cloud Apps, an activity policy is a policy type that lets you create custom detection rules based on specific user activities, with thresholds and parameters you define. For example, you can set a threshold for multiple failed sign-ins or unusual file downloads, and it triggers alerts when those conditions are met. Unlike built-in anomaly detection which uses machine learning, activity policies are fully customizable by the administrator to match your organization's risk requirements.
- ✗
App permissions policy
Why it's wrong here
App permissions policies in Defender for Cloud Apps are designed to govern OAuth app permissions, such as reviewing, authorizing, or revoking access granted to third-party applications like Google apps or Slack. They focus on consent grants and permission levels for cloud apps, not on monitoring user behavior counts or volume thresholds. As a result, this policy type cannot be used to set custom activity thresholds for user actions like sign-ins or downloads.
- ✗
Session policy
Why it's wrong here
Session policies are used for real-time control of user sessions, such as enforcing conditional access, blocking downloads, or redirecting risky sessions to an isolated browsing session. They act on the actual proxy-managed session in progress, rather than evaluating historical activity patterns or counts over time. Consequently, session policies do not support custom activity thresholds for alerting; they govern live interactions as they happen instead.
- ✗
Anomaly detection policy
Why it's wrong here
Anomaly detection policy in Defender for Cloud Apps is a preconfigured, machine learning–based policy that detects unusual behavioral patterns, such as impossible travel or mass file deletion. It relies on behavioral analytics to identify deviations from each user's typical baseline, but it does not expose configurable numeric thresholds for administrators to set. Therefore, while it detects anomalous activity, it cannot be used to define custom activity thresholds, making it the wrong choice for this requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.