Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A security administrator wants to prevent users from uploading files to unsanctioned cloud storage apps (e.g., personal Dropbox or Google Drive) from managed Windows devices. The solution must use a reverse proxy to control file uploads in real time. Which Microsoft Defender for Cloud Apps feature should the administrator configure?

⚠ Common exam trap

Candidates often confuse session policies (real-time reverse proxy control) with access policies (pre-session conditional access), leading candidates to choose access policy because it also uses Conditional Access, but it cannot inspect or block file uploads within an active session.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Session policy

Session policy in Microsoft Defender for Cloud Apps uses reverse proxy capabilities to monitor and control user activities in real time. When configured with the 'Control file upload' action, it can block or restrict uploads to unsanctioned cloud storage apps like personal Dropbox or Google Drive from managed Windows devices, meeting the requirement exactly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    App discovery policy

    Why it's wrong here

    App discovery policies in Defender for Cloud Apps are designed to identify shadow IT by analyzing cloud traffic from endpoints and firewalls, then cataloging the apps in use and their risk scores. They provide visibility and governance actions like unsanctioning an app, but they do not intercept or inspect individual user actions such as file uploads. The discovery engine works off logs, not a live reverse proxy, so it cannot prevent a user from uploading a file; it only tells you that the app is being used. Therefore, it does not meet the requirement to block uploads.

  • ✗

    Access policy

    Why it's wrong here

    Access policies in Microsoft Defender for Cloud Apps enforce allow/block decisions at the point of sign-in or first access to a cloud app, using signals like user risk, device compliance, or location. They are implemented through Conditional Access App Control or built-in connectors and can deny a user entry entirely, but they cannot selectively block an activity like uploading while still letting the user browse or view content. Because access policies operate on a binary grant-or-deny model, they lack the granular, per-request inspection needed to stop an upload to unsanctioned cloud storage mid-session. That granular activity-level control is the job of a session policy, not an access policy.

  • ✓

    Session policy

    Why this is correct

    Session policies are the correct mechanism to prevent uploads because they utilize the Conditional Access App Control reverse proxy to intercept every HTTP request and response within an active cloud app session. The reverse proxy inspects the request payload and can identify a file upload attempt to unsanctioned storage, then block the action in real time or prompt the user with a warning. This capability is session-scoped, meaning it can allow other activities like reading or downloading while specifically blocking uploads. Thus a session policy provides the precise, real-time enforcement the requirement demands.

  • ✗

    Activity policy

    Why it's wrong here

    Activity policies in Defender for Cloud Apps continuously monitor the log of activities collected from connected cloud apps and trigger alerts or automated actions when a rule condition is met, such as a user uploading a file to an unsanctioned app. These policies are reactive and API-driven: they evaluate activity metadata after the fact and can respond by suspending a user or flagging an incident, but they do not sit in the live data path to block the upload as it occurs. As a result, an activity policy might notify an admin about the upload after the fact, but it will not prevent the user from uploading the file in the first place. Real-time prevention requires a session policy's reverse proxy enforcement, not an activity policy.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.