Courseiva
Protect devices →hardMultiple Choice

MD-102 Protect devices Practice Question

Your organization uses Microsoft Defender for Cloud Apps. You need to configure a policy that automatically blocks downloads of sensitive data from SharePoint Online to unmanaged devices. Which policy type should you use?

⚠ Common exam trap

It's easy for candidates to confuse Access policies (which control sign-in and token issuance) with Session policies (which control in-session actions like downloads), leading candidates to incorrectly choose Access policy when the question explicitly requires blocking a specific file operation on unmanaged devices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Session policy

Session policies in Microsoft Defender for Cloud Apps allow real-time monitoring and control of user activities based on app and device context. By configuring a session policy with the condition 'Device tag equals Unmanaged' and the control 'Block download', you can automatically block downloads of sensitive data from SharePoint Online to unmanaged devices, leveraging reverse proxy architecture to inspect and intercept traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Activity policy

    Why it's wrong here

    Activity policies detect activity after it occurs and generate alerts or governance actions; they do not block a download in real time. It is tempting because activity policies are the standard tool for monitoring SharePoint Online events, but blocking requires a session or access control mechanism, not post-event detection.

  • ✗

    App discovery policy

    Why it's wrong here

    App discovery policies analyse traffic logs to identify shadow IT and unsanctioned cloud apps; they neither target SharePoint Online downloads nor enforce blocking. It is tempting because discovery is a core Defender for Cloud Apps capability, but it addresses visibility of unknown apps, not control of sensitive data transfers to unmanaged devices.

  • ✗

    Access policy

    Why it's wrong here

    Access policies control session behaviour for conditional access app control, governing actions during an active session rather than detecting and blocking the download event itself. It is tempting because session control can block downloads, but that requires the app to be onboarded for proxy, whereas the stated requirement is a policy that automatically blocks the download.

  • ✓

    Session policy

    Why this is correct

    A session policy in Defender for Cloud Apps applies Conditional Access App Control, proxying the SharePoint Online session so downloads to unmanaged devices can be blocked in real time. Access policies only evaluate sign-in conditions, so they cannot intercept an in-session download action.

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.