MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that automatically blocks downloads of files containing sensitive information from SharePoint Online to unmanaged devices. What type of policy should you create?
⚠ Common exam trap
MS-102 often tests the distinction between session policies (real-time, proxy-based controls) and activity policies (alerting/governance) or Purview DLP policies (data-centric, not session-based).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session policy
A session policy in Microsoft Defender for Cloud Apps is used to enforce real-time controls on user sessions, including blocking downloads of files with sensitive information from SharePoint Online to unmanaged devices. Session policies leverage Conditional Access App Control to proxy the session and apply DLP-like controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Session policy
Why this is correct
Session policies apply real-time controls during a user session, including blocking downloads of files containing sensitive information from SharePoint Online to unmanaged devices. Access and activity policies cannot enforce this inline download restriction, so a session policy is required.
- ✗
Microsoft Purview Data Loss Prevention policy
Why it's wrong here
A Microsoft Purview Data Loss Prevention policy evaluates sensitive information and can block sharing, but it does not enforce session-level download blocking to unmanaged devices in Defender for Cloud Apps. It suits labelling and content-based protection across workloads, not conditional access app control enforcement.
- ✗
Activity policy
Why it's wrong here
Activity policies govern user actions in Defender for Cloud Apps sessions, such as blocking downloads based on app, user or device context, but they do not inspect file content for sensitive information. They suit scenarios restricting behaviour by session attributes rather than data classification.
- ✗
File policy
Why it's wrong here
File policies scan stored files in connected apps and can quarantine or alert on sensitive content, but they act on files at rest rather than intercepting a download in progress. They suit detecting and remediating exposed files, not blocking real-time transfer to unmanaged devices.
Go deeper
Related to this question
Learn chapter
Exchange Online Protection and Anti-Phishing
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
SharePoint Online
SharePoint Online is a cloud-based collaboration platform from Microsoft that lets teams create, store, organize, and share content securely from anywhere.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.