SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company uses Microsoft Defender for Cloud Apps to monitor their cloud environment. The security team wants to detect when a user downloads an unusually large amount of data from SharePoint Online compared to their normal behavior. They need to configure a policy that triggers an alert based on this anomaly. Which type of policy should they create in Defender for Cloud Apps?
⚠ Common exam trap
A common mix-up: candidates confuse anomaly detection policies with activity policies, which are also used to monitor activities but do not use machine learning to detect behavioral anomalies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anomaly detection policy
Anomaly detection policies in Microsoft Defender for Cloud Apps leverage machine learning to identify deviations from normal user behavior, such as mass downloads. They are designed to detect threats like data exfiltration. Other policy types are rule-based or content-focused and do not provide behavioral anomaly detection, making them unsuitable for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Anomaly detection policy
Why this is correct
Anomaly detection policies in Microsoft Defender for Cloud Apps use machine learning to establish baseline behavior and detect deviations, such as mass downloads. They can be configured to trigger alerts when activities like download volume significantly exceed a user's normal pattern. This directly addresses the requirement to detect unusual data downloads.
- ✗
File policy
Why it's wrong here
File policies are used to scan files for sensitive information or malware and apply governance actions. They focus on content inspection and protection, not on user behavior anomalies like abnormal download volumes. They would not detect a user downloading a large amount of data unless the files themselves match a policy.
- ✗
Session policy
Why it's wrong here
Session policies in Defender for Cloud Apps provide real-time control over user sessions, such as blocking downloads of sensitive files. They are applied during active sessions and are based on conditional access. They do not analyze historical behavior to detect anomalies; instead, they enforce controls in real time.
- ✗
Activity policy
Why it's wrong here
Activity policies in Defender for Cloud Apps are used to monitor and act on specific user activities based on predefined filters, such as file types or user groups. They do not use machine learning to detect anomalies like unusual download volumes. While they can trigger alerts, they are rule-based and not suited for behavioral anomaly detection.
Go deeper
Related to this question
Learn chapter
Azure Policy for Compliance
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
Key term
Defender for Cloud
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides unified security management and threat protection across hybrid and multi-cloud environments.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.