Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your organization uses Microsoft Defender for Cloud Apps. Security team wants to be alerted when a user accesses a cloud app from a risky IP address. Which solution should you use to create a policy that triggers an alert based on this activity?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create an activity policy.

Activity policies in Microsoft Defender for Cloud Apps monitor specific user activities (such as logins or file downloads) and can trigger alerts based on risk factors like the user's IP address. To be alerted when a user accesses a cloud app from a risky IP, an activity policy is appropriate. Session policies (Option B) control real-time session access and can block or allow actions but are not designed for alerting based on IP alone. App discovery policies (Option C) identify shadow IT and unsanctioned apps, not user activity alerts. Access policies (Option D) enforce conditional access requirements but do not primarily generate IP-based alerts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create an activity policy.

    Why this is correct

    Activity policies in Microsoft Defender for Cloud Apps are designed to monitor user and admin activities across connected cloud applications. They allow organizations to define specific conditions, such as access from a risky IP address or unusual download volumes, and then trigger alerts or automated governance actions when these conditions are met. This makes them ideal for detecting and responding to suspicious behavior or policy violations after an activity has occurred, providing crucial visibility into potential threats.

  • Create a session policy.

    Why it's wrong here

    Session policies in Microsoft Defender for Cloud Apps provide real-time, granular control over user sessions within cloud applications. These policies are enforced during a session, allowing actions like blocking downloads, protecting uploads, or requiring step-up authentication based on specific conditions, such as device compliance or location. However, they are not designed to retrospectively monitor and alert on completed activities or detect access from a risky IP after the fact; their primary function is to control ongoing user interactions.

  • Create an app discovery policy.

    Why it's wrong here

    App discovery policies within Microsoft Defender for Cloud Apps are specifically engineered to identify and categorize cloud applications being used within an organization, often referred to as "shadow IT." Their primary function is to discover unsanctioned apps, assess their risk, and provide insights into their usage patterns. While crucial for understanding an organization's cloud footprint, these policies do not monitor individual user activities or generate alerts based on specific access conditions like a risky IP address.

  • Create an access policy.

    Why it's wrong here

    Access policies in Microsoft Defender for Cloud Apps are used to enforce real-time access controls to cloud applications before a user gains entry. These policies can block access entirely or redirect users to a different experience based on conditions such as device state, location, or user group membership. While they prevent unauthorized access, they do not retrospectively monitor individual activities or generate alerts for suspicious actions that have already occurred, such as a completed access from a risky IP address.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.