Using Anomaly Detection Policies for Mass File Downloads
A company uses Microsoft Defender for Cloud Apps to monitor SaaS app usage. The security team wants to receive an alert when a user downloads more than 10 files from SharePoint Online within 5 minutes. Which type of policy should they create?
Quick Answer
The answer is an anomaly detection policy. This is the correct choice because Defender for Cloud Apps uses machine learning to establish a baseline of normal user behavior, and an anomaly detection policy for mass file downloads triggers alerts when activity deviates from that baseline—such as downloading more than 10 files from SharePoint Online within five minutes—without requiring you to hard-code a specific threshold. On the SC-900 exam, this question tests your understanding of how Microsoft’s security solutions differentiate between rule-based activity policies and adaptive anomaly detection; a common trap is confusing anomaly detection with activity policies, but remember that anomaly policies learn from historical patterns rather than relying on fixed rules. For a quick memory tip, think “anomaly = abnormal patterns, activity = fixed rules.”
⚠ Common exam trap
Candidates often confuse anomaly detection policies with session policies, mistakenly thinking that real-time control is required for alerting, when in fact anomaly detection policies are specifically designed for threshold-based behavioral alerts without blocking the action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anomaly detection policy
An anomaly detection policy in Microsoft Defender for Cloud Apps is designed to identify unusual user behaviors, such as a spike in file downloads within a short time window. This policy uses machine learning to establish a baseline of normal activity and triggers alerts when deviations like downloading more than 10 files from SharePoint Online in 5 minutes occur, making it the correct choice for this use case.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Session policy
Why it's wrong here
Session policies control app access and actions in real time, not for alerting on anomalous activity.
- ✓
Anomaly detection policy
Why this is correct
Anomaly detection policies identify unusual user behavior, such as mass downloads, based on learned baselines.
- ✗
OAuth app policy
Why it's wrong here
OAuth app policies govern third-party app permissions, not user behavior.
- ✗
File policy
Why it's wrong here
File policies monitor file metadata and sharing, not aggregate download counts.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
SharePoint Online
SharePoint Online is a cloud-based collaboration platform from Microsoft that lets teams create, store, organize, and share content securely from anywhere.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses Microsoft Defender for Cloud Apps to protect its SaaS apps. The security team needs to detect when a user downloads more than 100 files from SharePoint Online within 10 minutes. Which policy type should they create?
medium- ✓ A.Anomaly detection policy
- B.Activity policy
- C.Threat detection policy
- D.Compliance policy
Why A: Anomaly detection policies in Microsoft Defender for Cloud Apps use machine learning to establish a baseline of normal user behavior and then trigger alerts when deviations occur, such as a user downloading over 100 files from SharePoint Online within 10 minutes. This specific scenario—unusually high download volume in a short time—is a classic example of a behavioral anomaly that an anomaly detection policy is designed to catch, as it may indicate a data exfiltration attempt.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.