Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRHard

A security analyst is investigating a suspected credential stuffing attack against several cloud applications. The analyst needs to identify users who have attempted to log in from unusual locations or with an unusually high number of failed login attempts. Which type of policy in Microsoft Defender for Cloud Apps (MDCAS) is best suited to detect these anomalies?

  1. ASession policies
  2. BFile policies
  3. CActivity policies
  4. DCloud Discovery policies
Show answer & explanation

Correct answer: C. Activity policies

Activity policies in Microsoft Defender for Cloud Apps (MDCAS) are designed to detect anomalous user activities, such as impossible travel, unusual ISP, or excessive failed login attempts, which are direct indicators of credential stuffing or compromised accounts.

Why the other options are wrong

  • A. Session policies provide real-time control over user sessions to sanctioned apps (e.g., blocking downloads), but they don't primarily detect anomalous login patterns.
  • B. File policies focus on detecting and protecting sensitive data within files (e.g., sharing sensitive files publicly), not login anomalies.
  • D. Cloud Discovery policies are for identifying and assessing the risk of discovered cloud apps (shadow IT), not for detecting anomalies in user login activities.

Activity Policies (MDCAS)

Policies in Microsoft Defender for Cloud Apps that detect anomalous user behavior and activities across connected cloud applications, often indicating compromised accounts or insider threats.

  • Monitors login activities, file access, and administrative actions.
  • Can detect impossible travel, unusual locations, and excessive failed logins.
  • Generates alerts and can trigger automated actions.

Memory trick: To detect unusual cloud activities, you need a keen eye on every activity.

More Mitigate threats using Microsoft Defender XDR questions