Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A company uses Microsoft Defender for Cloud Apps (MDCAS) to monitor cloud application usage. They have identified a significant increase in data uploads to an unsanctioned cloud storage service by several users, which violates company policy. The security team wants to automatically block any future uploads to this specific unsanctioned service and alert administrators when such attempts occur. Which MDCAS policy type should be configured to achieve this goal?

  1. AAccess policy
  2. BCloud Discovery anomaly detection policy
  3. CActivity policy
  4. DFile policy
Show answer & explanation

Correct answer: C. Activity policy

Activity policies in Microsoft Defender for Cloud Apps allow administrators to define rules based on specific user activities (like 'upload') to specific applications (the unsanctioned service) and then apply actions such as blocking or alerting.

Why the other options are wrong

  • A. Access policies control user access to cloud apps based on conditions but not specific activities like 'upload' within an app.
  • B. Cloud Discovery anomaly detection policies detect unusual behavior but do not provide direct blocking capabilities for specific unsanctioned apps and activities.
  • D. File policies focus on sensitive content within files, not blocking uploads to specific unsanctioned services based on the activity itself.

Activity Policy (MDCAS)

A type of policy in Microsoft Defender for Cloud Apps that allows granular control over user activities within connected cloud applications.

  • Monitors specific user actions (e.g., upload, download, share).
  • Can enforce actions like block, alert, or require justification.
  • Applies to sanctioned and unsanctioned apps.

Memory trick: MDCAS Policies Actively Control App Data.

More Mitigate threats using Microsoft Defender XDR questions