Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company uses Microsoft Defender for Cloud Apps to monitor their cloud environment. The security team wants to detect when a user downloads an unusually large amount of data from SharePoint Online compared to their normal behavior. They need to configure a policy that triggers an alert based on this anomaly. Which type of policy should they create in Defender for Cloud Apps?

⚠ Common exam trap

A common mix-up: candidates confuse anomaly detection policies with activity policies, which are also used to monitor activities but do not use machine learning to detect behavioral anomalies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Anomaly detection policy

Anomaly detection policies in Microsoft Defender for Cloud Apps leverage machine learning to identify deviations from normal user behavior, such as mass downloads. They are designed to detect threats like data exfiltration. Other policy types are rule-based or content-focused and do not provide behavioral anomaly detection, making them unsuitable for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Anomaly detection policy

    Why this is correct

    Anomaly detection policies in Microsoft Defender for Cloud Apps use machine learning to establish baseline behavior and detect deviations, such as mass downloads. They can be configured to trigger alerts when activities like download volume significantly exceed a user's normal pattern. This directly addresses the requirement to detect unusual data downloads.

  • ✗

    File policy

    Why it's wrong here

    File policies are used to scan files for sensitive information or malware and apply governance actions. They focus on content inspection and protection, not on user behavior anomalies like abnormal download volumes. They would not detect a user downloading a large amount of data unless the files themselves match a policy.

  • ✗

    Session policy

    Why it's wrong here

    Session policies in Defender for Cloud Apps provide real-time control over user sessions, such as blocking downloads of sensitive files. They are applied during active sessions and are based on conditional access. They do not analyze historical behavior to detect anomalies; instead, they enforce controls in real time.

  • ✗

    Activity policy

    Why it's wrong here

    Activity policies in Defender for Cloud Apps are used to monitor and act on specific user activities based on predefined filters, such as file types or user groups. They do not use machine learning to detect anomalies like unusual download volumes. While they can trigger alerts, they are rule-based and not suited for behavioral anomaly detection.

Go deeper

Related to this question

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.