MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization has deployed Microsoft Defender for Cloud Apps. You need to ensure that all external file sharing to untrusted domains is automatically blocked. The solution must not affect internal sharing. What should you configure?
⚠ Common exam trap
Watch out — candidates often confuse access policies (which block user access to the app) with file policies (which govern sharing actions on files), leading them to select Option A instead of the correct file policy governance action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a file policy in Microsoft Defender for Cloud Apps with a governance action to remove external users.
A file policy in Microsoft Defender for Cloud Apps can be configured with a governance action to remove external users from shared files when sharing is detected with untrusted domains. This action automatically blocks external sharing without affecting internal sharing, as it targets only external collaborators from domains not on the trusted list.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an access policy in Microsoft Defender for Cloud Apps to block access from untrusted domains.
Why it's wrong here
Access policies in Microsoft Defender for Cloud Apps are conditional access rules that restrict user sign-in and session access based on conditions like IP address or device state. They operate at the authentication layer and do not modify existing file permissions or prevent users from creating external share links while allowed in the session. Therefore, an access policy targeting untrusted domains does not actively remove external users from already shared files, making it ineffective for the stated requirement.
- ✓
Create a file policy in Microsoft Defender for Cloud Apps with a governance action to remove external users.
Why this is correct
A file policy in Defender for Cloud Apps scans cloud app repositories for content, exposure, and sharing metadata, and can automatically apply governance actions when conditions are met. By configuring a condition that flags files shared with external domains or unauthorized collaborators, you can select the governance action "Remove external users" to directly strip external principals from the file's access control list (ACL). This is the appropriate mechanism because it is data-centric, works on both existing and new shares, and does not rely on user or session behavior.
- ✗
Configure an app connector for the cloud app to enforce DLP policies.
Why it's wrong here
Enabling an app connector in Microsoft Defender for Cloud Apps establishes an API-based connection that brings the cloud app's activity logs and metadata into the security platform for visibility and management. However, the app connector itself is only a prerequisite; it performs no enforcement, DLP, or sharing-control actions unless you separately configure policies that use the connector's data. Merely connecting the app does not block external sharing or remove external users, so it cannot be the solution by itself.
- ✗
Create a session policy in Microsoft Defender for Cloud Apps to monitor external sharing.
Why it's wrong here
Session policies in Defender for Cloud Apps apply at the proxy layer to monitor and control user actions in real time, such as blocking downloads, uploads, or copy/paste during an active session. While you could use a session policy to alert on external sharing attempts, session controls are ephemeral and do not retroactively modify file permissions or remove external users who have already been granted access. This option only offers monitoring, not the required automated remediation of file-sharing exposure.
Go deeper
Related to this question
Learn chapter
Defender for Endpoint Deployment via Intune
Key term
External sharing
External sharing is the process of granting access to an organization's internal resources, such as documents or sites, to users who are not part of the organization's own identity system.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.