exam questions

Exam MS-100 All Questions

View all questions & answers for the MS-100 exam

Exam MS-100 topic 2 question 37 discussion

Actual exam question from Microsoft's MS-100
Question #: 37
Topic #: 2
[All MS-100 Questions]

You have a Microsoft 365 tenant.
You have a line-of-business application named App1 that users access by using the My Apps portal.
After some recent security breaches, you implement a conditional access policy for App1 that uses Conditional Access App Control.
You need to be alerted by email if impossible travel is detected for a user of App1. The solution must ensure that alerts are generated for App1 only.
What should you do?

  • A. From Microsoft Cloud App Security, modify the impossible travel alert policy.
  • B. From Microsoft Cloud App Security, create a Cloud Discovery anomaly detection policy.
  • C. From the Azure Active Directory admin center, modify the conditional access policy.
  • D. From Microsoft Cloud App Security, create an app discovery policy.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
joelfrancisco
Highly Voted 5 years, 7 months ago
https://docs.microsoft.com/en-us/cloud-app-security/anomaly-detection-policy Impossible travel is on anomaly detection policy see link
upvoted 29 times
WoneSix
5 years, 2 months ago
Thanks, joel - that's the link that should ahve been referenced in the answer. :-(
upvoted 1 times
...
...
asdkjhbfc
Highly Voted 4 years, 12 months ago
Hi guys and gals, I tested this answer in my tenant and i've come to a conclusion; Answer A. Is in fact the correct answer. "Modify the impossible travel alert policy" See the how-to over here: http://www.rebeladmin.com/2018/09/step-step-guide-manage-impossible-travel-activity-alert-using-azure-cloud-app-security/ (i am not this guy thogh) The fact remains that with an anomaly detection - impossible travel you cannot select a specific app to monitor for impossible travel (you CAN select a Cloud app but there's no option to monitor for impossible travel) Also see this: https://docs.microsoft.com/nl-nl/cloud-app-security/cloud-discovery-anomaly-detection-policy There no option to monitor for impossible travel here. I've tested this in my tenant and the option does not present itself.
upvoted 17 times
shaan6810
4 years, 4 months ago
You're contradicting yourself here. You say the answer is A, then mention that you cannot select a specific app for it.
upvoted 1 times
Josey001
4 years ago
Here answer is A: Udemy practice tests answer is B: Other practice tests i piad for answre is again A.Are any of these practice tests worth bothering with, so many differing answers, i have found over half a dozen answers to questions that differ from other practice tests i have paid for.Test prep training has over a dozen answers in one exam that differe from both here & Udemy
upvoted 3 times
...
lucidgreen
4 years, 2 months ago
asdkjhbfc said that you cannot link an app in anomaly policy but you can in impossible travel policy.
upvoted 2 times
...
...
...
NrdAlrt
Most Recent 1 year, 10 months ago
I think it's A. Seems like a classic MS cert question where two answers are potentially right, but one is more right due precedence in what needs to be done first and foremost in order to accomplish the goal. I hate that THIS is how they challenge your knowledge of the subject matter. Making a test confusing and misleading doesn't mean the results indicate who is a better SME.
upvoted 1 times
...
ijarosova
2 years, 2 months ago
Selected Answer: A
I vote A.
upvoted 1 times
...
Meebler
2 years, 2 months ago
B, Option A (creating a Cloud Discovery anomaly detection policy) is incorrect because it is used to detect anomalous behaviors across all apps and cannot be configured to generate alerts for a specific app like App1. Option C (creating an app discovery policy) is incorrect because it is used to discover and assess apps used by employees in an organization, but not to generate alerts for impossible travel. Option D (modifying the conditional access policy from the Azure Active Directory admin center) is incorrect because conditional access policies are used to control access to apps based on certain conditions, but they cannot be configured to generate alerts for impossible travel events.
upvoted 1 times
Meebler
2 years, 2 months ago
To be alerted by email if impossible travel is detected for a user of App1 while ensuring that alerts are generated for App1 only, you should modify the impossible travel alert policy in Microsoft Cloud App Security. Therefore, the correct answer is B. From Microsoft Cloud App Security, modify the impossible travel alert policy. By modifying the impossible travel alert policy in Microsoft Cloud App Security, you can configure email alerts for impossible travel events that are specific to App1. Conditional Access App Control can be configured as part of the policy to enforce restrictions on App1's access if the user's travel is flagged as impossible.
upvoted 1 times
...
...
T10T
2 years, 9 months ago
Selected Answer: B
The answer is B. It's a trick question, they are misleading you with "impossible travel". Yes, there is a default "Impossible Travel" policy, but even if you modify you cannot restrict it to a single application. You would have to create a new "Cloud Discovery anomaly detection policy", which includes the "impossible travel" as part of its scope and then create a filter for "App1".
upvoted 8 times
...
Storm
2 years, 11 months ago
Answer has to be B A. You cannot Modify Impossible travel alert policy B. That will work C. You cannot setup email alert in conditional access policy D. The app is allready discovered. Thus dosen't make any sense. https://docs.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy#impossible-travel find : Scope anomaly detection policies in the link
upvoted 5 times
...
Chris1972
2 years, 11 months ago
all of the above
upvoted 1 times
...
DenisRossi
2 years, 11 months ago
Selected Answer: B
B is the correct. 1 - Never change a default policy, always create a new custom policy. 2 - The question ask to notify only if the App1 has a impossible travel alert, this is possible creating a new anomaly detection policy and setting the filter option with the App1 name.
upvoted 4 times
MirS
2 years, 11 months ago
Ans: B, refer to https://docs.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy#impossible-travel
upvoted 2 times
...
TechMinerUK
2 years, 11 months ago
I concur with DenisRoss. When possible you shouldn't be editing the default policies as you are essentially narrowing down the protection they give based on the new configuration. Any specific granular policies should be created additionally to the default policy to add more protection rather than removing it from all other apps. Because the question here is about only targeting App1 you should create an additional anomaly detection policy which is just targetted at App1 for impossible travel. Yes, changing the default policy would work however it would not be the best solution since it is reducing the protection for other apps
upvoted 2 times
...
...
salla
3 years, 2 months ago
Selected Answer: A
tested
upvoted 1 times
...
rockey90
3 years, 2 months ago
the answer is A explanation : 1-from (Microsoft 365 admin center > security ) it pops up a new window 2-you scroll down and click on (more resources) 3-you chose (microsoft defender for clouds Apps ) 4- you navigate in (control>policies) 5-you scroll down to (impossible travel ) and then modify it by adding the email address
upvoted 1 times
mikaiwhodakno
2 years, 11 months ago
But there is no option there as stated in the question to only protect App1, therefore B is the answer.
upvoted 2 times
...
T10T
2 years, 9 months ago
It's a trick question because you are just looking for "Impossible Travel" in the GUI, when in fact that feature is included in the Anomaly detection policy. You will need to create a new policy and filter for App1.
upvoted 1 times
...
...
AlexLiourtas
3 years, 4 months ago
Selected Answer: B
tested, ans B
upvoted 1 times
...
kanag1
3 years, 4 months ago
Selected Answer: A
Answer "A"is correct. Policy Type : Anomaly detection Exact Policy name : Impossible travel. There are several "anomaly detection" polices available and dont need to configure all of them to achieve what is asked for (Refer the link in answer for all policy details). , As the question looks for the exact policy name, the answer is : Impossible travel Policy.
upvoted 1 times
mikaiwhodakno
2 years, 11 months ago
But there is no option there as stated in the question to only protect App1, therefore B is the answer. The question is regarding the App1, not the user(s) using the App1.
upvoted 2 times
...
...
AZalan
3 years, 10 months ago
There is already default "Impossible travel" policy and to apply it to a specific user who uses App1. change Scope to "specific users & groups" and "filter" the specific user. So ANS=A
upvoted 1 times
...
rebadow
3 years, 11 months ago
It has to be A, the question states that the policy is already created. The task is to simply modify the existing policy so that it alerts. Choosing B is if there was no policy in place, and even then the answer would be iffy, since when you create an anomaly detection policy you also choose what kind, one does not cover all.
upvoted 3 times
...
BGM_YKA
4 years ago
I think there is some confusion here... the question is asking how to add email alerts to the already created conditional access policy for App1 that uses Conditional Access App Control. I think the correct answer should be modify the MCAS Session Policy based on the conditional access policy… But that’s not an option. C. is wrong since alerting is not part of conditional access policy A. maybe since it’s the only MCAS modify where B. and D. are MCAS create
upvoted 1 times
...
lucidgreen
4 years, 2 months ago
Always create a custom policy. Never modify default policies.
upvoted 3 times
lucidgreen
4 years, 2 months ago
Let me clarify. You don't want to restrict your default policies to a single app. So best to create a new one.
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...