Design security operations, identity, and compliance capabilities →hardMultiple ChoiceObjective-mapped
Block Data Exfiltration from Sanctioned Cloud Apps
Your organization uses Microsoft Defender for Cloud Apps. You need to detect and block data exfiltration from sanctioned cloud apps to personal devices. What should you configure?
Quick Answer
The answer is to create a session policy with app governance to block download. This configuration is correct because session policies in Microsoft Defender for Cloud Apps operate in real time, using reverse proxy technology to inspect and control data transfer activities as they happen, allowing you to block data exfiltration from sanctioned cloud apps to personal devices by preventing downloads or pasting of sensitive content. On the Microsoft Cybersecurity Architect exam, this scenario tests your understanding of how conditional access app control integrates with Defender for Cloud Apps to enforce granular data protection policies, often appearing as a distractor against file policies or discovery policies—remember, file policies are for static compliance checks on data at rest, not real-time blocking. A common trap is confusing session policies with OAuth app policies, which manage app permissions rather than data movement. Memory tip: think "session = real-time shield" for blocking exfiltration, while "file = static audit" for stored data.
⚠ Common exam trap
It's easy for candidates to confuse file policies (which detect sensitive data after it is stored) with session policies (which prevent exfiltration in real time), leading them to choose Option C instead of D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a session policy with app governance to block download.
A session policy with app governance in Microsoft Defender for Cloud Apps allows you to monitor and control user activities in real time. By configuring a session policy to block downloads, you can prevent data exfiltration from sanctioned cloud apps to personal devices, as the policy inspects HTTP/HTTPS traffic and enforces access controls based on user context and device compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an OAuth app policy to revoke permissions.
Why it's wrong here
OAuth policies manage app permissions, not data exfiltration.
- ✗
Create an app discovery policy to identify unsanctioned apps.
Why it's wrong here
Discovery policies identify apps, not block exfiltration.
- ✗
Create a file policy to detect sensitive data in sanctioned apps.
Why it's wrong here
File policies detect but do not block in real time.
- ✓
Create a session policy with app governance to block download.
Why this is correct
Session policies can block data exfiltration in real time.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Defender for Cloud Apps. You need to identify users who are downloading large amounts of data from a sanctioned cloud app in a short period. What should you configure?
medium- ✓ A.Create an anomaly detection policy for impossible travel or unusual activity.
- B.Create an app permission policy to block downloads.
- C.Create an activity policy to monitor downloads.
- D.Create a file policy to detect mass download.
Why A: Anomaly detection policies in Microsoft Defender for Cloud Apps are designed to detect unusual activities, including large data downloads from sanctioned apps, by analyzing behavioral patterns over time. Option A is correct because it leverages built-in anomaly detection for volume-based alerts. Option B (app permission policy) manages OAuth app permissions, not download volume. Option C (activity policy) can monitor specific activities but is less specialized for mass download detection. Option D (file policy) focuses on file attributes and metadata, not download quantity.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.