MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Cloud Apps. You want to control the use of personal cloud storage apps. Which TWO actions should you take?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a session policy to monitor and control downloads to personal cloud storage apps.
The correct answers are D and E. Option D is correct because session policies in Microsoft Defender for Cloud Apps (via Conditional Access App Control) allow you to monitor and control downloads to personal cloud storage apps in real time. Option E is correct because app governance provides visibility into app permissions and behaviors, enabling you to monitor and control which apps can access cloud storage. Option A is incorrect because a DLP policy prevents sharing of sensitive data but does not control the use of personal cloud storage apps directly. Option B is incorrect because a conditional access policy requiring managed apps controls access to corporate resources but does not specifically govern personal cloud storage usage. Option C is incorrect because blocking all personal cloud storage apps is overly restrictive; Defender for Cloud Apps supports granular controls through policies rather than blanket blocks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a DLP policy to prevent sharing of sensitive data to personal cloud storage apps.
Why it's wrong here
DLP protects data but does not control the usage of the apps themselves.
- ✗
Create a conditional access policy to require managed apps for cloud storage.
Why it's wrong here
Conditional access can require app protection policies but does not directly block unsanctioned apps.
- ✗
Block all personal cloud storage apps using Defender for Cloud Apps.
Why it's wrong here
Blocking all such apps may hinder productivity; a more granular approach is recommended.
- ✓
Create a session policy to monitor and control downloads to personal cloud storage apps.
Why this is correct
Session policies can monitor and restrict activities within cloud apps in real time.
- ✓
Use app governance to monitor and control app permissions.
Why this is correct
App governance allows you to oversee and restrict app permissions in your environment.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
DLP policy
A DLP policy is a set of rules that an organization uses to prevent sensitive data from being lost, stolen, or accidentally exposed, whether it is in use, in motion, or at rest.
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
About these practice questions
This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.