You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. You need to be notified if a user downloads more than 50 files in one minute from Site1.
Which type of policy should you create in the Microsoft Defender for Cloud Apps portal?
Correct Answer: C
To detect and get alerts when a user downloads a large number of files in a short period of time (for example, more than 50 files within one minute) in Microsoft SharePoint Online, you must configure an Activity policy in Microsoft Defender for Cloud Apps (MCAS).
* Activity policies monitor specific user actions (upload, download, delete, share, etc.) and can trigger alerts based on thresholds or frequency.
* Anomaly detection policies detect behavioral anomalies automatically (not threshold-based).
* Session policies apply real-time controls during sessions (e.g., block download).
* File policies monitor or classify files at rest.
From Microsoft's documentation:
"Activity policies let you monitor specific activities in your cloud apps and define actions or alerts when certain criteria are met, such as excessive downloads or mass deletions." Thus, for detecting a user who downloads more than 50 files in one minute - an Activity policy is required.