Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A security administrator wants to monitor and control user downloads from a third-party SaaS application (e.g., Box) in real time. The administrator needs to apply session-level policies to block downloads based on risk. Which Microsoft 365 Defender feature should be used?

⚠ Common exam trap

Test-takers frequently confuse App Connectors (API-based control) with Conditional Access App Control (proxy-based session control), mistakenly thinking API integration can enforce real-time download blocks when it only provides retrospective or policy-based actions on stored data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conditional Access App Control

Conditional Access App Control (CAAC) is the correct feature because it enables real-time session-level monitoring and control of user activities within third-party SaaS applications like Box. By integrating with Microsoft Defender for Cloud Apps, CAAC can apply policies to block downloads based on risk signals such as user location, device compliance, or anomalous behavior, all within the user's active session.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cloud Discovery

    Why it's wrong here

    Cloud Discovery inventories and analyzes shadow IT usage in your environment, using firewall/proxy logs to identify the apps users access and assess associated risks. It produces rich reports on app normalization, governance, and user behavior, but it is fundamentally a post-hoc analytics engine rather than an inline enforcement point. Because it cannot place itself in the user's live authentication and data path, it cannot intercept or block a file download during a session.

  • Conditional Access App Control

    Why this is correct

    Conditional Access App Control is the session-control engine in Microsoft Defender for Cloud Apps, integrated directly with Azure AD Conditional Access. When a user signs in, Azure AD routes the session through the Defender for Cloud Apps reverse proxy, allowing identity-aware policies to inspect the user's actions in real time and enforce constraints such as block download, monitor only, or require protection. This makes it the correct choice for monitoring and controlling user downloads from a third-party SaaS application at the individual session level.

  • App Connectors

    Why it's wrong here

    App connectors leverage APIs provided by SaaS vendors to give Defender for Cloud Apps read access to a connected app's files, activities, and configuration, enabling automated scanning, labeling, and post-event governance through actions like quarantine or encryption. These API calls are asynchronous and external to the user's browser session, so while an app connector can detect and remediate a sensitive file that was already uploaded or shared, it cannot sit inside the live session and block the user's download as it happens. It therefore fails the requirement for real-time session-level control.

  • Anomaly Detection Policies

    Why it's wrong here

    Anomaly detection policies use machine-learning baselines of user activity to identify unusual or suspicious behavior such as impossible travel, multiple failed sign-ins, or mass file downloads. When triggered, these policies can raise an alert and invoke automated governance actions, like disabling a user's account, but the action is triggered after the activity has been observed, not in the request/response path of the session. As a result, they provide detection and response, but cannot offer a per-session download block on a third-party SaaS app.

About these practice questions

One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.