Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A security administrator needs to block unsanctioned cloud apps in real time using a reverse proxy. Which two Microsoft Defender for Cloud Apps components must be configured?

⚠ Common exam trap

Many candidates confuse Cloud Discovery (which only detects unsanctioned apps via log analysis) with the real-time blocking capability, or they assume App governance provides reverse proxy controls when it actually focuses on OAuth app permissions and lifecycle management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access App Control

Conditional Access App Control (B) is the reverse proxy component in Microsoft Defender for Cloud Apps that enforces real-time session-level monitoring and control of cloud app access. Session control policies (D) are the specific policy objects that define the actions (e.g., block download, block access) applied through that reverse proxy. Together, they enable blocking unsanctioned cloud apps in real time by intercepting user traffic via the reverse proxy architecture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud Discovery

    Why it's wrong here

    Cloud Discovery is a feature in Microsoft Defender for Cloud Apps that identifies cloud app usage and shadow IT by analyzing traffic logs from firewalls and proxies. It provides visibility and risk assessments but operates asynchronously on historical data, so it cannot enforce real-time blocking of unsanctioned apps during a live user session.

  • ✓

    Conditional Access App Control

    Why this is correct

    Conditional Access App Control is the reverse proxy component of Microsoft Defender for Cloud Apps that, when integrated with Microsoft Entra Conditional Access, intercepts user sessions to cloud apps in real time. It enables granular controls such as blocking access entirely, preventing downloads, or masking sensitive data, making it the correct infrastructure for real-time blocking of unsanctioned cloud apps.

  • ✗

    App governance

    Why it's wrong here

    App governance is a feature of Microsoft Defender for Cloud Apps that oversees OAuth-enabled applications accessing Microsoft 365 by monitoring their compliance and managing permissions. It focuses on app behavior and consent, not on network traffic inspection or session interception, so it cannot block unsanctioned cloud apps in real time.

  • ✓

    Session control policies

    Why this is correct

    Session control policies in Defender for Cloud Apps define specific actions, such as blocking, restricting, or monitoring activities within a cloud app session, and are enforced through Conditional Access App Control. However, the policy itself is not the reverse proxy; it is a configuration that leverages the proxy infrastructure to act in real time, so the underlying enabler is the app control component.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.