Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company uses Microsoft Defender for Cloud Apps to protect its SaaS apps. The security team needs to detect when a user downloads more than 100 files from SharePoint Online within 10 minutes. Which policy type should they create?

⚠ Common exam trap

It's easy for candidates to confuse 'activity policy' with 'anomaly detection policy,' assuming any user action-based alert is an activity policy, but activity policies require explicit, static conditions (e.g., 'download from SharePoint') and cannot dynamically detect unusual volume or frequency without additional logic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Anomaly detection policy

Anomaly detection policies in Microsoft Defender for Cloud Apps use machine learning to establish a baseline of normal user behavior and then trigger alerts when deviations occur, such as a user downloading over 100 files from SharePoint Online within 10 minutes. This specific scenario—unusually high download volume in a short time—is a classic example of a behavioral anomaly that an anomaly detection policy is designed to catch, as it may indicate a data exfiltration attempt.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Anomaly detection policy

    Why this is correct

    Anomaly detection policies in Microsoft Defender for Cloud Apps leverage advanced machine learning algorithms to establish a baseline of normal user and entity behavior within your cloud environment. These policies continuously monitor for significant deviations from this established baseline, such as impossible travel, unusual administrative activities, or mass downloads to an unmanaged device. By identifying these statistical anomalies, they proactively detect potential threats like compromised accounts, insider threats, or data exfiltration attempts that might otherwise go unnoticed.

  • Activity policy

    Why it's wrong here

    Activity policies are designed to monitor and enforce specific, predefined actions or events within your cloud applications, based on explicit rules you configure. Unlike anomaly detection, they do not use machine learning to identify unusual behavior but instead trigger alerts or actions when a user performs a particular activity that matches a set condition, such as accessing a specific sensitive file or uploading data to an unsanctioned application. Their purpose is to track and control known patterns of activity rather than discovering novel, anomalous ones.

  • Threat detection policy

    Why it's wrong here

    Threat detection policies in Microsoft Defender for Cloud Apps primarily focus on identifying known malicious patterns, indicators of compromise (IOCs), or specific attack techniques that have been previously identified by threat intelligence feeds or security research. These policies are effective at blocking or alerting on established threats and malware signatures, but they do not inherently use behavioral baselining or machine learning to uncover *unusual* user actions. They are reactive to known threat definitions rather than proactive in discovering deviations from normal behavior.

  • Compliance policy

    Why it's wrong here

    Compliance policies are primarily concerned with ensuring that an organization's data handling, sharing, and storage practices adhere to regulatory requirements, industry standards, or internal governance rules. These policies typically involve identifying sensitive data, enforcing data loss prevention (DLP) rules, ensuring proper data classification, and managing access controls based on data sensitivity. They are focused on data governance and regulatory adherence, not on monitoring user behavior for security anomalies or detecting unusual activity patterns.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.