MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Cloud Apps. You discover that a user is downloading large amounts of data from SharePoint Online to an unmanaged device. You need to automatically block the download and alert the security team. What should you configure?
⚠ Common exam trap
The trap is confusing file policies (which scan content) with session policies (which enforce real-time controls), or picking anomaly detection which only alerts and does not block.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session policy
A session policy in Defender for Cloud Apps applies real-time controls during a user session, including the ability to block downloads to unmanaged devices and trigger alerts. This is the correct control for stopping an active data exfiltration attempt from SharePoint Online.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Session policy
Why this is correct
Session policies apply real-time, in-session controls through Conditional Access app control, blocking downloads to unmanaged devices and raising alerts. This satisfies the requirement to automatically prevent the SharePoint Online download while notifying the security team.
- ✗
Access policy
Why it's wrong here
Access policies govern sign-in to apps based on user, device and location conditions, controlling whether a session starts at all. They cannot inspect an in-progress SharePoint download and block that specific transfer, which requires a session policy.
- ✗
File policy
Why it's wrong here
File policies apply to files already stored in connected cloud services, governing sharing, external access and malware, and they cannot intercept a live SharePoint download session. Session policies evaluate user activity in real time and can block the transfer, which is what this scenario requires.
- ✗
Anomaly detection policy
Why it's wrong here
Anomaly detection policies raise alerts when behaviour deviates from a learned baseline, such as unusual download volume, but they only notify; they cannot automatically block the transfer. Blocking a live download requires a session policy with a block action.
Go deeper
Related to this question
Learn chapter
Microsoft Purview Data Map
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.