SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Cloud Apps. You need to receive alerts when a user accesses a cloud app from a location that is not whitelisted. What should you configure?
⚠ Common exam trap
Many exam-takers confuse activity policies (which alert) with access or session policies (which enforce controls), leading candidates to choose an option that blocks access instead of generating an alert.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an activity policy in Microsoft Defender for Cloud Apps.
An activity policy in Microsoft Defender for Cloud Apps monitors user activities and can trigger alerts based on specific conditions, such as access from non-whitelisted locations. This policy type evaluates activities against defined criteria (e.g., IP address ranges) and generates alerts without blocking access, which matches the requirement to receive alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a conditional access policy in Microsoft Entra ID.
Why it's wrong here
Conditional Access policies in Microsoft Entra ID are identity-driven controls that evaluate signals like user risk, device compliance, and location to grant or block sign-in access. They do not create alerts for suspicious activities; they enforce access decisions at authentication time. An alerting mechanism for anomalous location-based app usage would not be generated by this policy type.
- ✗
Set up a session policy in Microsoft Defender for Cloud Apps.
Why it's wrong here
A session policy in Defender for Cloud Apps provides real-time monitoring and control over user activities within a connected app session, such as preventing downloads or enforcing session timeout. It does not generate alert records or notifications for specific user actions; instead, it applies conditional access controls during the session. This makes it a corrective control, not a detective one that raises location-based alerts.
- ✗
Configure an access policy in Microsoft Defender for Cloud Apps.
Why it's wrong here
An access policy in Defender for Cloud Apps is designed to enforce real-time access rules, like blocking sign-ins from unrecognized locations or requiring step-up authentication. Although it can detect risk signals, it acts by denying or allowing access rather than producing standalone alert artifacts. It is a preventive measure, not an alerting mechanism for ongoing monitoring and investigation.
- ✓
Create an activity policy in Microsoft Defender for Cloud Apps.
Why this is correct
Creating an activity policy in Microsoft Defender for Cloud Apps is correct because activity policies are purpose-built to monitor user activities and trigger alerts when specific conditions, such as an unusual location, are met. You can define rules based on attributes like IP address, geographic location, device, and activity type to generate alerts for investigation. This directly fulfills the requirement of alerting on location-based anomalies.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.