Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization has Microsoft 365 E5 and uses Microsoft Defender for Cloud Apps. You want to block downloads from an unsanctioned cloud app that is used by some employees. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the app as unsanctioned in Defender for Cloud Apps and create a session policy to block downloads.

Marking the app as unsanctioned in Defender for Cloud Apps and creating a session policy allows blocking downloads from that app. Option A is incorrect because a DLP policy protects data but does not block app usage. Option B is incorrect because a conditional access policy can enforce controls like requiring managed apps, but it does not directly block downloads from an unsanctioned app. Option C is incorrect because blocking by IP address is ineffective for cloud apps that use dynamic IP ranges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a DLP policy to block sharing of sensitive data with the app.

    Why it's wrong here

    A DLP policy inspects content for sensitive information types and blocks sharing, not the download action itself, so unsanctioned app downloads continue. It is tempting because DLP governs data egress, which suits preventing sensitive files leaving Microsoft 365 rather than controlling app usage.

  • ✗

    Create a conditional access policy to require the use of managed apps.

    Why it's wrong here

    Conditional Access managed-app requirements govern access to Microsoft 365 resources from devices, not downloads from a third-party unsanctioned app. It is tempting because it restricts unmanaged client access, which suits protecting corporate data on personal devices rather than shadow-IT app control.

  • ✗

    Block the app by its IP addresses in the firewall.

    Why it's wrong here

    Firewall IP blocking severs all traffic to the app, including legitimate business use, and cannot target the download action; IPs also change frequently. It is tempting because it is a blunt network control, which suits blocking clearly malicious destinations rather than managing sanctioned or unsanctioned SaaS usage.

  • ✓

    Configure the app as unsanctioned in Defender for Cloud Apps and create a session policy to block downloads.

    Why this is correct

    Marking the app unsanctioned alone only flags it in Cloud Discovery; the session policy is what enforces control. Conditional Access app control proxies the session, and the block-download action satisfies the requirement to prevent data leaving via that unsanctioned cloud app.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.