Courseiva

SC-200 Respond to security incidents Practice Question

A security analyst receives an alert from Microsoft Defender for Cloud Apps indicating that a user has signed in from a banned country. The analyst needs to block further access from that country for all users. What should the analyst configure?

⚠ Common exam trap

Watch out — candidates often confuse the scope of conditional access policies (which block at the authentication level) with the session-level control provided by Defender for Cloud Apps, leading them to select option D instead of C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an IP range group for the country and configure a session policy to block it.

Microsoft Defender for Cloud Apps session policies can block access based on IP address geolocation. By creating an IP range group for the banned country and configuring a session policy to block traffic from that group, the analyst can enforce real-time blocking of all user sessions originating from that country, leveraging the reverse proxy architecture of Defender for Cloud Apps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the device compliance policy in Microsoft Intune.

    Why it's wrong here

    Intune device compliance policies are evaluated by Microsoft Entra Conditional Access to ensure devices meet health and configuration standards—such as OS version, encryption status, or threat level—but they do not possess any geographic awareness. A compliance policy cannot filter on the user's source IP address or country, and it certainly does not provide a session-level block within a cloud app. Trying to modify it would have zero impact on where a user is connecting from.

  • ✗

    Configure a data loss prevention (DLP) policy in Microsoft Purview.

    Why it's wrong here

    A Microsoft Purview DLP policy inspects content for sensitive data (like credit card numbers, PII, or confidential documents) and applies protective actions such as blocking sharing, preventing copy/paste, or encrypting content. It is data-centric, not session-centric, and has no concept of a user's network location or country. While DLP can stop data exfiltration, it cannot block access to an app entirely based on the geo-location of the request—that is the role of a session policy in Defender for Cloud Apps.

  • ✓

    Create an IP range group for the country and configure a session policy to block it.

    Why this is correct

    In Microsoft Defender for Cloud Apps, the correct approach is to create an IP address group that represents the country in question, using Defender for Cloud Apps' built-in country-based IP classification or by uploading custom ranges. Then, you configure a session policy with an access-control action set to 'Block' and a filter that matches the 'IP group' to the newly created group. When a session policy is active, Defender for Cloud Apps intercepts the session in real time and denies access from that country, providing granular, app-specific enforcement.

  • ✗

    Create a conditional access policy in Microsoft Entra ID to block the country.

    Why it's wrong here

    Microsoft Entra Conditional Access policies can indeed block access by country through 'Named Locations,' and this is a viable alternative at the identity layer. However, the question specifically asks for a capability within Microsoft Defender for Cloud Apps, and the answer should be the mechanism native to that product. Conditional Access operates before the session is established, while Defender for Cloud Apps session policies operate inside the app session itself, enabling actions like session blocking, restriction, or monitoring that are not available with standard Conditional Access.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.