MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security administrator wants to configure Microsoft Defender for Cloud Apps so that when a user accesses a sensitive file in a sanctioned cloud app from an unmanaged device, the user is blocked from downloading the file and a block action is logged in real time. Which type of policy should the administrator configure?
⚠ Common exam trap
Watch out — candidates often confuse session policies with access policies or file policies, mistakenly thinking that blocking access to the entire app (Option C) or monitoring after the fact (Option B) achieves the same real-time blocking of a specific download action, when only a session policy provides the required granular, in-session control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a session policy with the action 'Block' on the download action for files with a specific sensitivity label
A session policy in Microsoft Defender for Cloud Apps allows real-time control over user activities within a sanctioned cloud app. By configuring the action 'Block' on the download action for files with a specific sensitivity label, the administrator can block the download when the session is initiated from an unmanaged device, and the block action is logged in real time. This meets the requirement of blocking the download and logging the action simultaneously.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a session policy with the action 'Block' on the download action for files with a specific sensitivity label
Why this is correct
This session policy works through the Microsoft Defender for Cloud Apps reverse proxy, which intercepts and inspects user requests in real time. By combining a 'device as unmanaged' condition with a sensitivity-label file filter, it can block the actual download action at the moment it occurs while still letting the user access the file in the browser. This is the only option that fulfills the requirement of allowing access but preventing a download from an unmanaged device.
- ✗
Create a file policy that monitors for sensitive files being accessed from unmanaged devices and generates an alert
Why it's wrong here
File policies in Defender for Cloud Apps continuously scan and monitor files at rest in connected cloud apps, comparing them against content or metadata like sensitivity labels. When a match is found, they can raise alerts or apply governance actions such as quarantining a file or revoking its sharing links, but they operate after the file has been processed and are not aware of live user sessions. As a result, they cannot intercept and block a download as it is happening, so they do not meet the stated requirement.
- ✗
Configure an access policy that blocks access to the cloud app from unmanaged devices
Why it's wrong here
An access policy in Defender for Cloud Apps is essentially a conditional access policy applied at sign-in time, based on conditions like device, IP address, or user group. Blocking access from unmanaged devices would deny the user entry to the entire cloud app, whereas the requirement is to allow the user to work normally and block only the download action. Additionally, such an access policy does not examine individual file actions, so it cannot provide granular, session-level control over downloads.
- ✗
Configure an activity policy that monitors download activities from unmanaged devices and triggers automatic remediation
Why it's wrong here
Activity policies monitor the stream of audit log events and compare them against known risks or custom rules, triggering responses like alerts, notifications, or automatic actions such as suspending a user. However, these triggers fire only after the download event has already been logged, meaning the action has completed; they cannot roll it back or prevent it in real time. Because the requirement is to stop the download before it happens, an activity policy is inherently unsuitable.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Sensitivity label
A sensitivity label is a metadata tag applied to digital content that classifies the content's level of confidentiality and governs how it can be shared, protected, and accessed.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.