exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 1 question 2 discussion

Actual exam question from Microsoft's SC-200
Question #: 2
Topic #: 1
[All SC-200 Questions]

You need to receive a security alert when a user attempts to sign in from a location that was never used by the other users in your organization to sign in.
Which anomaly detection policy should you use?

  • A. Impossible travel
  • B. Activity from anonymous IP addresses
  • C. Activity from infrequent country
  • D. Malware detection
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
teehex
Highly Voted 4 years ago
Activity from infrequent country is the correct answer. First, both "Impossible travel" and "Activity from infrequent country" are detection rule that help prevent breaches from foreign attackers. The difference between the rule is the type of historical data. "Impossible travel" actually compares between the new location's sign-in with the last known one. So it basically means if someone already logged into a location (corporate network with USA-based IP range) and now he is logged into a China network then it is likely the user is compromised (assume the organization doesn't have any traffic/record/association with China network). Moreover it is based on geographically distant locations within a time period shorter. So in my example China is too far from USA. "Activity from infrequent country" is a bit different. Instead of comparing with the last known location, it detects if an account is logged in from a country that has never been accessed by any user in the organization. This rule is based on user behavior using entity behavioral analytics and machine learning.
upvoted 56 times
teehex
4 years ago
In addition to my explanation: - Impossible travel often looks into one sign-in attempt from TWO different geo-based location. - Activity from infrequent country often looks into a location that no one ever used. So basically it just perform a check among all historical locations and does the comparison.
upvoted 13 times
...
peponokefalos
1 year, 7 months ago
Really nice explanation. Thank you for that!
upvoted 2 times
...
dandirindan
3 years, 1 month ago
great explanation
upvoted 2 times
...
...
TheMCT
Highly Voted 4 years, 2 months ago
Given Answer, C, is correct
upvoted 36 times
Startkabels
3 years, 8 months ago
Agree, I work with these policies daily
upvoted 5 times
...
prabhjot
3 years, 4 months ago
this is correct as explained here also - https://docs.microsoft.com/en-us/defender-cloud-apps/investigate-anomaly-alerts
upvoted 4 times
...
...
hieulecloud
Most Recent 4 months, 2 weeks ago
Selected Answer: C
Link here https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy
upvoted 1 times
...
mikl
6 months, 3 weeks ago
Selected Answer: C
Explanation: The "Activity from infrequent country" anomaly detection policy generates alerts when a user attempts to sign in from a location (country or region) that has not been previously used by other users in the organization. This is designed to detect potentially suspicious or unauthorized login attempts.
upvoted 1 times
...
nk_exam
7 months, 1 week ago
Selected Answer: C
C is correct
upvoted 1 times
...
Nikki0222
7 months, 3 weeks ago
Answer is C
upvoted 1 times
...
ESAJRR
1 year, 7 months ago
Selected Answer: C
C. Activity from infrequent country
upvoted 2 times
...
chepeerick
1 year, 7 months ago
Selected Answer: C
Option C
upvoted 2 times
...
Wedge34
1 year, 8 months ago
Selected Answer: C
C is the right answer
upvoted 2 times
...
tatendazw
2 years ago
Triggered by anomaly detection rule policy "Activity from infrequent country", this requires 7 days to learn the locations frequently used https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy#activity-from-infrequent-country
upvoted 1 times
...
cyber_mks
2 years, 2 months ago
C, is correct
upvoted 2 times
...
CarlosE
2 years, 4 months ago
Selected Answer: C
C is correct
upvoted 2 times
...
emmanuelodenyire
2 years, 4 months ago
Selected Answer: C
I will go with C
upvoted 1 times
...
simonseztech
2 years, 9 months ago
Selected Answer: C
https://docs.microsoft.com/en-us/defender-cloud-apps/investigate-anomaly-alerts
upvoted 1 times
...
Pandaguo
3 years, 2 months ago
C is right
upvoted 1 times
...
Tx4free
3 years, 3 months ago
Selected Answer: C
C is correct
upvoted 1 times
...
ubt
3 years, 4 months ago
Selected Answer: C
Activity from infrequent country This detection considers past activity locations to determine new and infrequent locations. The anomaly detection engine stores information about previous locations used by users in the organization. An alert is triggered when an activity occurs from a location that wasn't recently or never visited by any user in the organization.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...