Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium
A Microsoft 365 administrator is investigating a potential insider threat where an employee might be exfiltrating sensitive data by uploading it to an unsanctioned cloud storage service. The administrator needs to identify which specific files were uploaded and by whom. Which Microsoft Defender for Cloud Apps policy type should be configured to detect and log these activities?
- AAnomaly detection policy
- BApp governance policy
- CCloud Discovery policy
- DActivity policy
Show answer & explanationAnswer & explanation
Correct answer: D. Activity policy
Activity policies in Defender for Cloud Apps are designed to detect user activities, such as file uploads to specific cloud apps, based on predefined or custom filters, making them suitable for tracking sensitive data exfiltration.
Why the other options are wrong
- A. Anomaly detection policies identify unusual behavior patterns that deviate from normal user activity, but might not specifically log individual file uploads to unsanctioned apps.
- B. App governance policies focus on detecting and remediating risky app behaviors and data usage patterns within the Microsoft Graph ecosystem, not directly monitoring file uploads to unsanctioned cloud storage services.
- C. Cloud Discovery policies are used to identify and assess shadow IT applications, not to monitor specific user actions like file uploads within those apps.
Defender for Cloud Apps Activity Policies
Activity policies in Microsoft Defender for Cloud Apps allow you to monitor specific user activities across connected cloud applications based on granular conditions and take actions like alerting or blocking.
- Detects specific actions like file uploads, downloads, logins, and administrative actions.
- Can be customized with filters for users, groups, apps, activity types, and file properties.
- Used for compliance, data loss prevention (DLP), and insider threat detection.
Memory trick: To track SPECIFIC user ACTIONS, you need an ACTIVITY policy.