Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that detects when a user shares a file containing sensitive data with an external domain. Which three components must you configure in the policy? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A content inspection method (e.g., DLP)

The correct components for a file policy in Microsoft Defender for Cloud Apps are: a filter to specify the scope (e.g., sharing with external users), a content inspection method (e.g., DLP) to detect sensitive data, and a governance action (e.g., alert or block). Option D is incorrect because session control actions are used in session policies, not file policies. Option E is incorrect because access token conditions are not a component of file policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A content inspection method (e.g., DLP)

    Why this is correct

    Content inspection, such as DLP, examines the file payload to confirm it actually contains sensitive data, satisfying the stem's sensitive-data condition. Sharing filters alone cannot determine content; inspection is what distinguishes a genuine sensitive-data exposure from an ordinary external share.

  • ✓

    A governance action (e.g., alert, block)

    Why this is correct

    A governance action defines what happens when the policy matches, such as raising an alert or blocking the share. The stem requires detection, so the action determines whether the event is merely surfaced for review or actively prevented, completing the policy's response behaviour.

  • ✓

    A filter to specify the sharing type (e.g., external)

    Why this is correct

    The sharing-type filter scopes the policy to external sharing events specifically, matching the stem's requirement to detect files shared with an external domain. Without it, the policy would also trigger on internal sharing, producing false positives and failing to target the external-domain condition.

  • ✗

    A session control action

    Why it's wrong here

    Session control actions govern real-time proxy behaviour such as blocking downloads, and they require a session policy rather than a detection policy. They would be correct when inline control of an active session is needed, not when the requirement is merely to detect external sharing of sensitive content.

  • ✗

    An access token condition

    Why it's wrong here

    Access tokens govern session authentication and are evaluated by session policies, not by the file, activity and content inspection filters that detect external sharing of sensitive files. Token conditions belong in Conditional Access-style session controls, where identity and sign-in risk drive enforcement.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.