Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that automatically blocks downloads of files containing sensitive information from SharePoint Online to unmanaged devices. What type of policy should you create?

⚠ Common exam trap

MS-102 often tests the distinction between session policies (real-time, proxy-based controls) and activity policies (alerting/governance) or Purview DLP policies (data-centric, not session-based).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Session policy

A session policy in Microsoft Defender for Cloud Apps is used to enforce real-time controls on user sessions, including blocking downloads of files with sensitive information from SharePoint Online to unmanaged devices. Session policies leverage Conditional Access App Control to proxy the session and apply DLP-like controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Session policy

    Why this is correct

    Session policies apply real-time controls during a user session, including blocking downloads of files containing sensitive information from SharePoint Online to unmanaged devices. Access and activity policies cannot enforce this inline download restriction, so a session policy is required.

  • ✗

    Microsoft Purview Data Loss Prevention policy

    Why it's wrong here

    A Microsoft Purview Data Loss Prevention policy evaluates sensitive information and can block sharing, but it does not enforce session-level download blocking to unmanaged devices in Defender for Cloud Apps. It suits labelling and content-based protection across workloads, not conditional access app control enforcement.

  • ✗

    Activity policy

    Why it's wrong here

    Activity policies govern user actions in Defender for Cloud Apps sessions, such as blocking downloads based on app, user or device context, but they do not inspect file content for sensitive information. They suit scenarios restricting behaviour by session attributes rather than data classification.

  • ✗

    File policy

    Why it's wrong here

    File policies scan stored files in connected apps and can quarantine or alert on sensitive content, but they act on files at rest rather than intercepting a download in progress. They suit detecting and remediating exposed files, not blocking real-time transfer to unmanaged devices.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.