SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization uses Microsoft Defender for Cloud Apps. A security analyst needs to receive an alert whenever a user accesses a cloud app from a new IP address that is not in the organization's trusted IP range. What should the analyst configure?
⚠ Common exam trap
Many candidates confuse anomaly detection policies with session policies, mistakenly thinking session policies can alert on new IP addresses, but session policies only enforce controls during active sessions and do not generate standalone alerts for access from untrusted IPs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An anomaly detection policy
An anomaly detection policy in Microsoft Defender for Cloud Apps is designed to identify unusual user activities, such as access from a new IP address outside the organization's trusted IP range. This policy leverages machine learning to establish a baseline of normal behavior and triggers alerts when deviations occur, making it the correct choice for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A file policy
Why it's wrong here
A file policy in Microsoft Defender for Cloud Apps is designed to monitor and control activities related to files stored within connected cloud applications. Its primary function is to detect sensitive information exposure, identify malware, and enforce data loss prevention (DLP) rules on files, such as blocking sharing or requiring encryption. This type of policy does not analyze user sign-in properties or locations to identify anomalous access attempts from new IP addresses.
- ✗
A session policy
Why it's wrong here
A session policy in Microsoft Defender for Cloud Apps provides real-time monitoring and control over user sessions within cloud applications. These policies are used to enforce conditional access, such as blocking downloads, requiring step-up authentication, or protecting data during a session based on user, device, or location attributes. While they can react to conditions during a session, they are not designed to proactively detect and alert on the initial sign-in from an unfamiliar IP address as an anomalous event.
- ✗
An app permission policy
Why it's wrong here
An app permission policy in Microsoft Defender for Cloud Apps focuses on governing the permissions granted to third-party OAuth applications that integrate with your cloud environment. Its purpose is to identify and control which applications have access to organizational data, assessing their risk level and the scope of their permissions. This policy type is unrelated to monitoring individual user sign-in locations or detecting suspicious login attempts from new IP addresses.
- ✓
An anomaly detection policy
Why this is correct
An anomaly detection policy in Microsoft Defender for Cloud Apps leverages machine learning and behavioral analytics to identify unusual and potentially suspicious activities across your cloud applications. These policies establish a baseline of normal user behavior and then flag deviations, such as impossible travel, sign-ins from unfamiliar locations or IP addresses, and unusual activity volumes. Therefore, it is the correct policy type for detecting and alerting on sign-ins originating from new or previously unseen IP addresses.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.