Block Data Exfiltration from Sanctioned Cloud Apps
Your organization uses Microsoft Defender for Cloud Apps. You need to detect and block data exfiltration from sanctioned cloud apps to personal devices. What should you configure?
Quick Answer
The answer is to create a session policy with app governance to block download. This configuration is correct because session policies in Microsoft Defender for Cloud Apps operate in real time, using reverse proxy technology to inspect and control data transfer activities as they happen, allowing you to block data exfiltration from sanctioned cloud apps to personal devices by preventing downloads or pasting of sensitive content. On the Microsoft Cybersecurity Architect exam, this scenario tests your understanding of how conditional access app control integrates with Defender for Cloud Apps to enforce granular data protection policies, often appearing as a distractor against file policies or discovery policies—remember, file policies are for static compliance checks on data at rest, not real-time blocking. A common trap is confusing session policies with OAuth app policies, which manage app permissions rather than data movement. Memory tip: think "session = real-time shield" for blocking exfiltration, while "file = static audit" for stored data.
⚠ Common exam trap
It's easy for candidates to confuse file policies (which detect sensitive data after it is stored) with session policies (which prevent exfiltration in real time), leading them to choose Option C instead of D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a session policy with app governance to block download.
A session policy with app governance in Microsoft Defender for Cloud Apps allows you to monitor and control user activities in real time. By configuring a session policy to block downloads, you can prevent data exfiltration from sanctioned cloud apps to personal devices, as the policy inspects HTTP/HTTPS traffic and enforces access controls based on user context and device compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an OAuth app policy to revoke permissions.
Why it's wrong here
OAuth policies manage app permissions, not data exfiltration.
- ✗
Create an app discovery policy to identify unsanctioned apps.
Why it's wrong here
Discovery policies identify apps, not block exfiltration.
- ✗
Create a file policy to detect sensitive data in sanctioned apps.
Why it's wrong here
File policies detect but do not block in real time.
- ✓
Create a session policy with app governance to block download.
Why this is correct
Session policies can block data exfiltration in real time.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Defender for Cloud Apps. You need to identify users who are downloading large amounts of data from a sanctioned cloud app in a short period. What should you configure?
medium- ✓ A.Create an anomaly detection policy for impossible travel or unusual activity.
- B.Create an app permission policy to block downloads.
- C.Create an activity policy to monitor downloads.
- D.Create a file policy to detect mass download.
Why A: The correct option is A: create an anomaly detection policy for impossible travel or unusual activity. In Microsoft Defender for Cloud Apps, anomaly detection policies are specifically designed to use machine learning to surface unusual user behavior such as mass downloads, unusual file access, or activity spikes from sanctioned apps, which matches the requirement to identify users downloading large amounts of data in a short period. Option B is wrong because an app permission policy governs OAuth app permissions and blocks/revokes app access, not user download behavior. Option C is wrong because an activity policy applies static filters/actions to activities rather than detecting behavioral anomalies like abnormal download volume. Option D is wrong because a file policy applies to files in connected storage/services for governance and DLP-style controls, not to identifying anomalous mass-download user behavior.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.