MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security administrator wants to monitor and control user downloads from a third-party SaaS application (e.g., Box) in real time. The administrator needs to apply session-level policies to block downloads based on risk. Which Microsoft 365 Defender feature should be used?
⚠ Common exam trap
Test-takers frequently confuse App Connectors (API-based control) with Conditional Access App Control (proxy-based session control), mistakenly thinking API integration can enforce real-time download blocks when it only provides retrospective or policy-based actions on stored data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access App Control
Conditional Access App Control (CAAC) is the correct feature because it enables real-time session-level monitoring and control of user activities within third-party SaaS applications like Box. By integrating with Microsoft Defender for Cloud Apps, CAAC can apply policies to block downloads based on risk signals such as user location, device compliance, or anomalous behavior, all within the user's active session.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Discovery
Why it's wrong here
Cloud Discovery inventories and analyzes shadow IT usage in your environment, using firewall/proxy logs to identify the apps users access and assess associated risks. It produces rich reports on app normalization, governance, and user behavior, but it is fundamentally a post-hoc analytics engine rather than an inline enforcement point. Because it cannot place itself in the user's live authentication and data path, it cannot intercept or block a file download during a session.
- ✓
Conditional Access App Control
Why this is correct
Conditional Access App Control is the session-control engine in Microsoft Defender for Cloud Apps, integrated directly with Azure AD Conditional Access. When a user signs in, Azure AD routes the session through the Defender for Cloud Apps reverse proxy, allowing identity-aware policies to inspect the user's actions in real time and enforce constraints such as block download, monitor only, or require protection. This makes it the correct choice for monitoring and controlling user downloads from a third-party SaaS application at the individual session level.
- ✗
App Connectors
Why it's wrong here
App connectors leverage APIs provided by SaaS vendors to give Defender for Cloud Apps read access to a connected app's files, activities, and configuration, enabling automated scanning, labeling, and post-event governance through actions like quarantine or encryption. These API calls are asynchronous and external to the user's browser session, so while an app connector can detect and remediate a sensitive file that was already uploaded or shared, it cannot sit inside the live session and block the user's download as it happens. It therefore fails the requirement for real-time session-level control.
- ✗
Anomaly Detection Policies
Why it's wrong here
Anomaly detection policies use machine-learning baselines of user activity to identify unusual or suspicious behavior such as impossible travel, multiple failed sign-ins, or mass file downloads. When triggered, these policies can raise an alert and invoke automated governance actions, like disabling a user's account, but the action is triggered after the activity has been observed, not in the request/response path of the session. As a result, they provide detection and response, but cannot offer a per-session download block on a third-party SaaS app.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Device compliance
Device compliance is the process of ensuring that a device meets an organization's security and configuration policies before it can access network resources.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.