MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security administrator wants to prevent users from uploading files to unsanctioned cloud storage apps (e.g., personal Dropbox or Google Drive) from managed Windows devices. The solution must use a reverse proxy to control file uploads in real time. Which Microsoft Defender for Cloud Apps feature should the administrator configure?
⚠ Common exam trap
Candidates often confuse session policies (real-time reverse proxy control) with access policies (pre-session conditional access), leading candidates to choose access policy because it also uses Conditional Access, but it cannot inspect or block file uploads within an active session.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session policy
Session policy in Microsoft Defender for Cloud Apps uses reverse proxy capabilities to monitor and control user activities in real time. When configured with the 'Control file upload' action, it can block or restrict uploads to unsanctioned cloud storage apps like personal Dropbox or Google Drive from managed Windows devices, meeting the requirement exactly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
App discovery policy
Why it's wrong here
App discovery policies in Defender for Cloud Apps are designed to identify shadow IT by analyzing cloud traffic from endpoints and firewalls, then cataloging the apps in use and their risk scores. They provide visibility and governance actions like unsanctioning an app, but they do not intercept or inspect individual user actions such as file uploads. The discovery engine works off logs, not a live reverse proxy, so it cannot prevent a user from uploading a file; it only tells you that the app is being used. Therefore, it does not meet the requirement to block uploads.
- ✗
Access policy
Why it's wrong here
Access policies in Microsoft Defender for Cloud Apps enforce allow/block decisions at the point of sign-in or first access to a cloud app, using signals like user risk, device compliance, or location. They are implemented through Conditional Access App Control or built-in connectors and can deny a user entry entirely, but they cannot selectively block an activity like uploading while still letting the user browse or view content. Because access policies operate on a binary grant-or-deny model, they lack the granular, per-request inspection needed to stop an upload to unsanctioned cloud storage mid-session. That granular activity-level control is the job of a session policy, not an access policy.
- ✓
Session policy
Why this is correct
Session policies are the correct mechanism to prevent uploads because they utilize the Conditional Access App Control reverse proxy to intercept every HTTP request and response within an active cloud app session. The reverse proxy inspects the request payload and can identify a file upload attempt to unsanctioned storage, then block the action in real time or prompt the user with a warning. This capability is session-scoped, meaning it can allow other activities like reading or downloading while specifically blocking uploads. Thus a session policy provides the precise, real-time enforcement the requirement demands.
- ✗
Activity policy
Why it's wrong here
Activity policies in Defender for Cloud Apps continuously monitor the log of activities collected from connected cloud apps and trigger alerts or automated actions when a rule condition is met, such as a user uploading a file to an unsanctioned app. These policies are reactive and API-driven: they evaluate activity metadata after the fact and can respond by suspending a user or flagging an incident, but they do not sit in the live data path to block the upload as it occurs. As a result, an activity policy might notify an admin about the upload after the fact, but it will not prevent the user from uploading the file in the first place. Real-time prevention requires a session policy's reverse proxy enforcement, not an activity policy.
Go deeper
Related to this question
Learn chapter
Attack Simulation Training in Defender
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.