exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 5 question 2 discussion

Actual exam question from Microsoft's SC-200
Question #: 2
Topic #: 9
[All SC-200 Questions]

You need to modify the anomaly detection policy settings to meet the Cloud App Security requirements and resolve the reported problem.
Which policy should you modify?

  • A. Activity from suspicious IP addresses
  • B. Activity from anonymous IP addresses
  • C. Impossible travel
  • D. Risky sign-in
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Eltooth
Highly Voted 3 years, 7 months ago
Agree - C. Users connecting to two geographically separate locations at the same time would trigger the impossible travel alert, however as these are legitimate then this setting needs to be altered to include both network addresses.
upvoted 30 times
Tuitor01
4 months, 4 weeks ago
It's also because it's the only one that matches the anomaly detecetion list for defender for cloud :D I hesitated a bit with Risky Sign-ins which is kind a close to Risky IP, but nah, the answer is B.
upvoted 1 times
Tuitor01
4 months, 4 weeks ago
I mean C....
upvoted 1 times
...
...
Discuss4certi
3 years, 6 months ago
I can follow this reasoning
upvoted 3 times
...
molariosso
2 years, 10 months ago
makes perfect sense
upvoted 4 times
...
...
Murtuza
Most Recent 1 year, 4 months ago
Cloud App Security frequently generates false positive alerts when users connect to both offices simultaneously.
upvoted 2 times
...
chepeerick
1 year, 6 months ago
Correct option
upvoted 1 times
...
jamclash
1 year, 7 months ago
in exam 9/20/23
upvoted 1 times
...
billo79152718
1 year, 9 months ago
Selected Answer: C
C. Imposible Travel
upvoted 2 times
...
[Removed]
2 years, 1 month ago
Selected Answer: C
The "Impossible travel" policy is designed to detect sign-ins where the travel time between two locations is deemed impossible by Azure AD. This policy helps to prevent unauthorized access to resources, and can be adjusted to meet the needs of the organization. By modifying this policy to account for simultaneous connections to both offices, you can reduce the frequency of false positive alerts while still maintaining a high level of security. Therefore, the correct answer is C. Impossible travel.
upvoted 4 times
...
gyaansastra
2 years, 1 month ago
Selected Answer: C
Two distinct sign-in events will be captured with same time generated flag for the same user. So it appears to be Atypical travel / impossible Travel use case.
upvoted 3 times
...
[Removed]
2 years, 2 months ago
Selected Answer: B
Based on the reported problem and the Cloud App Security requirements, the policy that needs to be modified is "Activity from anonymous IP addresses". This policy detects anomalous access to cloud apps from IP addresses that are not associated with the user's location. Since remote users of Litware connect to the network using VPNs from different locations, Cloud App Security may generate false positive alerts when users connect to both offices simultaneously. Modifying the "Activity from anonymous IP addresses" policy can help resolve this issue by excluding VPN IP addresses from being flagged as anonymous. Therefore, the correct answer is option B.
upvoted 1 times
wsrudmen
2 years, 2 months ago
Always bad response from this account with no sense response. Please admin, check this account. I report its comment as abusive.
upvoted 6 times
Walaakb
2 years, 1 month ago
he works for Microsoft :)
upvoted 3 times
evilprime
2 years, 1 month ago
its a chatgpt answer.
upvoted 1 times
...
...
...
...
Efficia
3 years, 5 months ago
Correct. Requirement: Cloud App Security must identify whether a user connection is anomalous based on tenant-level data. Resolve the requirement: In the Impossible Travel policy, you can set the sensitivity slider to determine the level of anomalous behavior needed before an alert is triggered https://docs.microsoft.com/en-us/cloud-app-security/anomaly-detection-policy#tune-anomaly-detection-policies
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago