SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization uses Microsoft Defender for Cloud Apps. Security team wants to be alerted when a user accesses a cloud app from a risky IP address. Which solution should you use to create a policy that triggers an alert based on this activity?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an activity policy.
Activity policies in Microsoft Defender for Cloud Apps monitor specific user activities (such as logins or file downloads) and can trigger alerts based on risk factors like the user's IP address. To be alerted when a user accesses a cloud app from a risky IP, an activity policy is appropriate. Session policies (Option B) control real-time session access and can block or allow actions but are not designed for alerting based on IP alone. App discovery policies (Option C) identify shadow IT and unsanctioned apps, not user activity alerts. Access policies (Option D) enforce conditional access requirements but do not primarily generate IP-based alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an activity policy.
Why this is correct
Activity policies in Microsoft Defender for Cloud Apps are designed to monitor user and admin activities across connected cloud applications. They allow organizations to define specific conditions, such as access from a risky IP address or unusual download volumes, and then trigger alerts or automated governance actions when these conditions are met. This makes them ideal for detecting and responding to suspicious behavior or policy violations after an activity has occurred, providing crucial visibility into potential threats.
- ✗
Create a session policy.
Why it's wrong here
Session policies in Microsoft Defender for Cloud Apps provide real-time, granular control over user sessions within cloud applications. These policies are enforced during a session, allowing actions like blocking downloads, protecting uploads, or requiring step-up authentication based on specific conditions, such as device compliance or location. However, they are not designed to retrospectively monitor and alert on completed activities or detect access from a risky IP after the fact; their primary function is to control ongoing user interactions.
- ✗
Create an app discovery policy.
Why it's wrong here
App discovery policies within Microsoft Defender for Cloud Apps are specifically engineered to identify and categorize cloud applications being used within an organization, often referred to as "shadow IT." Their primary function is to discover unsanctioned apps, assess their risk, and provide insights into their usage patterns. While crucial for understanding an organization's cloud footprint, these policies do not monitor individual user activities or generate alerts based on specific access conditions like a risky IP address.
- ✗
Create an access policy.
Why it's wrong here
Access policies in Microsoft Defender for Cloud Apps are used to enforce real-time access controls to cloud applications before a user gains entry. These policies can block access entirely or redirect users to a different experience based on conditions such as device state, location, or user group membership. While they prevent unauthorized access, they do not retrospectively monitor individual activities or generate alerts for suspicious actions that have already occurred, such as a completed access from a risky IP address.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.