Courseiva

Block Data Exfiltration from Sanctioned Cloud Apps

Your organization uses Microsoft Defender for Cloud Apps. You need to detect and block data exfiltration from sanctioned cloud apps to personal devices. What should you configure?

Quick Answer

The answer is to create a session policy with app governance to block download. This configuration is correct because session policies in Microsoft Defender for Cloud Apps operate in real time, using reverse proxy technology to inspect and control data transfer activities as they happen, allowing you to block data exfiltration from sanctioned cloud apps to personal devices by preventing downloads or pasting of sensitive content. On the Microsoft Cybersecurity Architect exam, this scenario tests your understanding of how conditional access app control integrates with Defender for Cloud Apps to enforce granular data protection policies, often appearing as a distractor against file policies or discovery policies—remember, file policies are for static compliance checks on data at rest, not real-time blocking. A common trap is confusing session policies with OAuth app policies, which manage app permissions rather than data movement. Memory tip: think "session = real-time shield" for blocking exfiltration, while "file = static audit" for stored data.

⚠ Common exam trap

It's easy for candidates to confuse file policies (which detect sensitive data after it is stored) with session policies (which prevent exfiltration in real time), leading them to choose Option C instead of D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a session policy with app governance to block download.

A session policy with app governance in Microsoft Defender for Cloud Apps allows you to monitor and control user activities in real time. By configuring a session policy to block downloads, you can prevent data exfiltration from sanctioned cloud apps to personal devices, as the policy inspects HTTP/HTTPS traffic and enforces access controls based on user context and device compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create an OAuth app policy to revoke permissions.

    Why it's wrong here

    OAuth policies manage app permissions, not data exfiltration.

  • Create an app discovery policy to identify unsanctioned apps.

    Why it's wrong here

    Discovery policies identify apps, not block exfiltration.

  • Create a file policy to detect sensitive data in sanctioned apps.

    Why it's wrong here

    File policies detect but do not block in real time.

  • Create a session policy with app governance to block download.

    Why this is correct

    Session policies can block data exfiltration in real time.

About these practice questions

Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Defender for Cloud Apps. You need to identify users who are downloading large amounts of data from a sanctioned cloud app in a short period. What should you configure?

medium
  • A.Create an anomaly detection policy for impossible travel or unusual activity.
  • B.Create an app permission policy to block downloads.
  • C.Create an activity policy to monitor downloads.
  • D.Create a file policy to detect mass download.

Why A: Anomaly detection policies in Microsoft Defender for Cloud Apps are designed to detect unusual activities, including large data downloads from sanctioned apps, by analyzing behavioral patterns over time. Option A is correct because it leverages built-in anomaly detection for volume-based alerts. Option B (app permission policy) manages OAuth app permissions, not download volume. Option C (activity policy) can monitor specific activities but is less specialized for mass download detection. Option D (file policy) focuses on file attributes and metadata, not download quantity.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.