nerdexam
Microsoft

SC-200 · Question #11

You need to receive a security alert when a user attempts to sign in from a location that was never used by the other users in your organization to sign in. Which anomaly detection policy should you…

The correct answer is C. Activity from infrequent country. 'Activity from infrequent country' detects sign-ins from geographic locations that are rare or never previously seen across the entire organization's user population – matching the scenario exactly. 'Impossible travel' flags a single user signing in from two distant locations…

Submitted by fernanda_arg· Apr 18, 2026Configure protections and detections

Question

You need to receive a security alert when a user attempts to sign in from a location that was never used by the other users in your organization to sign in. Which anomaly detection policy should you use?

Options

  • AImpossible travel
  • BActivity from anonymous IP addresses
  • CActivity from infrequent country
  • DMalware detection

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    94% (33)

Explanation

'Activity from infrequent country' detects sign-ins from geographic locations that are rare or never previously seen across the entire organization's user population – matching the scenario exactly. 'Impossible travel' flags a single user signing in from two distant locations in an implausibly short time. 'Activity from anonymous IP addresses' flags Tor/proxy usage, not unusual geography. 'Malware detection' identifies malicious file uploads and is unrelated to sign-in location.

Topics

#Anomaly Detection#Identity Protection#Sign-in Risk Policies#Location-based Security

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice