exam questions

Exam MS-101 All Questions

View all questions & answers for the MS-101 exam

Exam MS-101 topic 2 question 121 discussion

Actual exam question from Microsoft's MS-101
Question #: 121
Topic #: 2
[All MS-101 Questions]

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.

You need to be notified when a single user downloads more than 50 files during any 60-second period.

What should you configure?

  • A. a file policy
  • B. an anomaly detection policy
  • C. a session policy
  • D. an activity policy
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Fala_Fel
Highly Voted 2 years, 5 months ago
Selected Answer: D
Answer should be D - Tested in Lan Use the Defender for Cloud Apps Policy Template "Mass download by a single user: Alert when a single user performs more than 50 downloads within 1 minute." Filtering by Type shows it is an "Activity Policy"
upvoted 7 times
...
Amir1909
Most Recent 1 year, 4 months ago
D is correct
upvoted 1 times
...
jamspurple
2 years, 1 month ago
Tested in Lab, Anomaly Detection Policy - Will build a baseline over a 7 day period and will start to generate alerts on abnormal activities. This MAY meet your goal but you cannot guarantee that it will send an alert in this specific scenario. Activity Policy - Allows you to specify the specific requirements for the alert to be triggered, such as specifying 50 files in 1 minute. This is the right answer.
upvoted 2 times
...
Meebler
2 years, 3 months ago
B. an anomaly detection policy Go to the Microsoft Defender for Cloud Apps portal (https://security.microsoft.com/). Click on "Policies" from the left-hand menu, then click "Anomaly detections". Click "Create policy" and enter a name and description for the policy. Under the "User and entity" section, select the user or group you want to monitor. Under the "Activity" section, select "Download" for the activity type. Under the "Threshold" section, set the threshold to "50" for the number of files downloaded, and "60 seconds" for the time period. Optionally, you can configure other settings such as the severity level and the actions to take when the policy is triggered. Click "Create" to save the policy.
upvoted 1 times
Jakub2023
2 years ago
I checked this in my test tenant - and I honestly do not know what you're talking about. None of the settings that you mention for an anomaly detection policy are available. Things might have changed in the last three months - but by now B is not an option.
upvoted 1 times
...
Meebler
2 years, 3 months ago
Option D, an activity policy, could also be a good answer for this scenario. An activity policy can be used to monitor and alert on specific activities, such as file downloads, performed by users. However, an anomaly detection policy is specifically designed to detect unusual behavior and activity patterns that may indicate a potential threat or risk. In this case, since the requirement is to be notified when a single user downloads more than 50 files during any 60-second period, an anomaly detection policy may be a more appropriate choice.
upvoted 1 times
...
...
hufflepuff
2 years, 4 months ago
Selected Answer: D
https://learn.microsoft.com/en-us/defender-cloud-apps/user-activity-policies Activity policies allow custom alerts to be sent or actions taken when user activity is detected. For example, you want to know every time: - A user tries to sign in and fails 70 times in one minute - A user downloads 7,000 files - A user is logged in from an unfamiliar country/region
upvoted 2 times
EsamiTopici
2 years, 2 months ago
Hi hupple, I always answer to you, in your opinion why not anomaly detection? can do the same thing if I have not misunderstood
upvoted 1 times
EsamiTopici
2 years, 2 months ago
Huffle* :(
upvoted 1 times
...
...
...
JB12340987
2 years, 4 months ago
I think the supplied answer is correct. https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy
upvoted 1 times
EsamiTopici
2 years, 3 months ago
According to what would be right?
upvoted 1 times
...
...
egsalvadori
2 years, 5 months ago
Selected Answer: D
Activity Policy for sure: D
upvoted 3 times
...
Jame
2 years, 5 months ago
Selected Answer: D Activity policies can set activity and timeframe. Anomaly detection policy is only support Unusual activities https://learn.microsoft.com/en-us/defender-cloud-apps/user-activity-policies
upvoted 2 times
...
Fala_Fel
2 years, 5 months ago
Use the Defender for Cloud Apps Policy Template "Mass download by a single user: Alert when a single user performs more than 50 downloads within 1 minute." Filtering by Type shows it is an "Activity Policy"
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...