Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Exhibit

{
  "rules": [
    {
      "name": "Block high-risk downloads",
      "action": "block",
      "conditions": {
        "appRiskScore": "high",
        "activity": "download",
        "userRiskScore": "high"
      }
    }
  ]
}

Refer to the exhibit. You are configuring a session policy in Microsoft Defender for Cloud Apps. The policy must block downloads when both the app risk is high and the user risk is high. Based on the exhibit, which additional condition should you add to ensure the policy only applies to unsanctioned apps?

⚠ Common exam trap

The trap is assuming that app risk score correlates with sanction status; candidates might choose app risk score instead of app tag, but they are independent attributes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a condition for app tag to be 'unsanctioned'.

In Microsoft Defender for Cloud Apps session policies, to restrict the policy to unsanctioned apps, you must add a condition on the app tag. Unsanctioned apps are those that have been marked as unsanctioned in Cloud App Catalog. The condition 'app tag equals unsanctioned' ensures the policy only applies to those apps. The other conditions (app risk score, user risk score, activity) do not filter by sanction status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a condition for app risk score to be medium or low.

    Why it's wrong here

    Adding a condition for app risk score to be medium or low would actually broaden the scope of the session policy, not narrow it. The exhibit shows the policy already targets high-risk apps, so including medium or low risk would allow the policy to evaluate (and potentially block) sessions involving apps that are not necessarily high risk. To restrict to unsanctioned apps, the app tag is the correct attribute, not risk score.

  • ✗

    Add a condition for user risk score to be medium.

    Why it's wrong here

    A user risk score condition of medium would expand the policy to a broader set of users, since the existing policy already restricts to high user risk. This does nothing to limit the policy to unsanctioned apps; user risk is an identity-based signal, not an app-based classification. The required narrowing should be based on the app's tag, not the user's risk level.

  • ✗

    Add a condition for activity to include upload.

    Why it's wrong here

    Adding an activity condition to include upload would expand the policy to cover upload activities, whereas the existing policy already blocks downloads. The requirement is to restrict the policy to unsanctioned apps, not to add more activity types. Upload and download are both activity entities, but neither helps identify whether the app is sanctioned or unsanctioned.

  • ✓

    Add a condition for app tag to be 'unsanctioned'.

    Why this is correct

    Adding a condition for app tag to be 'unsanctioned' explicitly scopes the session policy to only those applications that are marked as unsanctioned in the app catalog. This is the precise way to limit the policy's effect, because app tags are designed for this classification. It ensures that the existing download-blocking rule applies only to unsanctioned apps, fulfilling the stated requirement.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.