MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that detects when a user shares a file containing sensitive data with an external domain. Which three components must you configure in the policy? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A content inspection method (e.g., DLP)
The correct components for a file policy in Microsoft Defender for Cloud Apps are: a filter to specify the scope (e.g., sharing with external users), a content inspection method (e.g., DLP) to detect sensitive data, and a governance action (e.g., alert or block). Option D is incorrect because session control actions are used in session policies, not file policies. Option E is incorrect because access token conditions are not a component of file policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A content inspection method (e.g., DLP)
Why this is correct
Content inspection, such as DLP, examines the file payload to confirm it actually contains sensitive data, satisfying the stem's sensitive-data condition. Sharing filters alone cannot determine content; inspection is what distinguishes a genuine sensitive-data exposure from an ordinary external share.
- ✓
A governance action (e.g., alert, block)
Why this is correct
A governance action defines what happens when the policy matches, such as raising an alert or blocking the share. The stem requires detection, so the action determines whether the event is merely surfaced for review or actively prevented, completing the policy's response behaviour.
- ✓
A filter to specify the sharing type (e.g., external)
Why this is correct
The sharing-type filter scopes the policy to external sharing events specifically, matching the stem's requirement to detect files shared with an external domain. Without it, the policy would also trigger on internal sharing, producing false positives and failing to target the external-domain condition.
- ✗
A session control action
Why it's wrong here
Session control actions govern real-time proxy behaviour such as blocking downloads, and they require a session policy rather than a detection policy. They would be correct when inline control of an active session is needed, not when the requirement is merely to detect external sharing of sensitive content.
- ✗
An access token condition
Why it's wrong here
Access tokens govern session authentication and are evaluated by session policies, not by the file, activity and content inspection filters that detect external sharing of sensitive files. Token conditions belong in Conditional Access-style session controls, where identity and sign-in risk drive enforcement.
Go deeper
Related to this question
Learn chapter
Named Locations and Network-Based Policies
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Access token
A digital key that a computer system gives you to prove your identity and grant you permission to access specific resources or perform actions.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.