MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization has Microsoft 365 E5 and uses Microsoft Defender for Cloud Apps. You want to block downloads from an unsanctioned cloud app that is used by some employees. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the app as unsanctioned in Defender for Cloud Apps and create a session policy to block downloads.
Marking the app as unsanctioned in Defender for Cloud Apps and creating a session policy allows blocking downloads from that app. Option A is incorrect because a DLP policy protects data but does not block app usage. Option B is incorrect because a conditional access policy can enforce controls like requiring managed apps, but it does not directly block downloads from an unsanctioned app. Option C is incorrect because blocking by IP address is ineffective for cloud apps that use dynamic IP ranges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a DLP policy to block sharing of sensitive data with the app.
Why it's wrong here
A DLP policy inspects content for sensitive information types and blocks sharing, not the download action itself, so unsanctioned app downloads continue. It is tempting because DLP governs data egress, which suits preventing sensitive files leaving Microsoft 365 rather than controlling app usage.
- ✗
Create a conditional access policy to require the use of managed apps.
Why it's wrong here
Conditional Access managed-app requirements govern access to Microsoft 365 resources from devices, not downloads from a third-party unsanctioned app. It is tempting because it restricts unmanaged client access, which suits protecting corporate data on personal devices rather than shadow-IT app control.
- ✗
Block the app by its IP addresses in the firewall.
Why it's wrong here
Firewall IP blocking severs all traffic to the app, including legitimate business use, and cannot target the download action; IPs also change frequently. It is tempting because it is a blunt network control, which suits blocking clearly malicious destinations rather than managing sanctioned or unsanctioned SaaS usage.
- ✓
Configure the app as unsanctioned in Defender for Cloud Apps and create a session policy to block downloads.
Why this is correct
Marking the app unsanctioned alone only flags it in Cloud Discovery; the session policy is what enforces control. Conditional Access app control proxies the session, and the block-download action satisfies the requirement to prevent data leaving via that unsanctioned cloud app.
Go deeper
Related to this question
Learn chapter
Data Loss Prevention Policies
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
DLP policy
A DLP policy is a set of rules that an organization uses to prevent sensitive data from being lost, stolen, or accidentally exposed, whether it is in use, in motion, or at rest.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.