Courseiva

Using Anomaly Detection Policies for Mass File Downloads

A company uses Microsoft Defender for Cloud Apps to monitor SaaS app usage. The security team wants to receive an alert when a user downloads more than 10 files from SharePoint Online within 5 minutes. Which type of policy should they create?

Quick Answer

The answer is an anomaly detection policy. This is the correct choice because Defender for Cloud Apps uses machine learning to establish a baseline of normal user behavior, and an anomaly detection policy for mass file downloads triggers alerts when activity deviates from that baseline—such as downloading more than 10 files from SharePoint Online within five minutes—without requiring you to hard-code a specific threshold. On the SC-900 exam, this question tests your understanding of how Microsoft’s security solutions differentiate between rule-based activity policies and adaptive anomaly detection; a common trap is confusing anomaly detection with activity policies, but remember that anomaly policies learn from historical patterns rather than relying on fixed rules. For a quick memory tip, think “anomaly = abnormal patterns, activity = fixed rules.”

⚠ Common exam trap

Candidates often confuse anomaly detection policies with session policies, mistakenly thinking that real-time control is required for alerting, when in fact anomaly detection policies are specifically designed for threshold-based behavioral alerts without blocking the action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Anomaly detection policy

An anomaly detection policy in Microsoft Defender for Cloud Apps is designed to identify unusual user behaviors, such as a spike in file downloads within a short time window. This policy uses machine learning to establish a baseline of normal activity and triggers alerts when deviations like downloading more than 10 files from SharePoint Online in 5 minutes occur, making it the correct choice for this use case.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Session policy

    Why it's wrong here

    Session policies control app access and actions in real time, not for alerting on anomalous activity.

  • Anomaly detection policy

    Why this is correct

    Anomaly detection policies identify unusual user behavior, such as mass downloads, based on learned baselines.

  • OAuth app policy

    Why it's wrong here

    OAuth app policies govern third-party app permissions, not user behavior.

  • File policy

    Why it's wrong here

    File policies monitor file metadata and sharing, not aggregate download counts.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses Microsoft Defender for Cloud Apps to protect its SaaS apps. The security team needs to detect when a user downloads more than 100 files from SharePoint Online within 10 minutes. Which policy type should they create?

medium
  • A.Anomaly detection policy
  • B.Activity policy
  • C.Threat detection policy
  • D.Compliance policy

Why A: Anomaly detection policies in Microsoft Defender for Cloud Apps use machine learning to establish a baseline of normal user behavior and then trigger alerts when deviations occur, such as a user downloading over 100 files from SharePoint Online within 10 minutes. This specific scenario—unusually high download volume in a short time—is a classic example of a behavioral anomaly that an anomaly detection policy is designed to catch, as it may indicate a data exfiltration attempt.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.