SC-200 Respond to security incidents Practice Question
Exhibit
Refer to the exhibit.
```json
{
"properties": {
"policyType": "Microsoft.CloudAppSecurity/Policy",
"policyName": "Block Unapproved Storage",
"policyMode": "Monitor",
"filter": {
"app": {
"category": "Cloud storage",
"tag": "Unsanctioned"
}
},
"actions": [
{
"actionType": "Block",
"actionValue": "true"
}
]
}
}An administrator creates a Microsoft Defender for Cloud Apps policy to block unsanctioned cloud storage apps. Despite the policy, users can still access these apps. What is the most likely cause?
⚠ Common exam trap
The trap here is that candidates often focus on the action type (e.g., 'Block' vs. 'Alert') or the app tagging, overlooking that the policy mode itself controls whether enforcement occurs, not just the action setting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy mode is set to 'Monitor', which only alerts and does not block
When a Microsoft Defender for Cloud Apps policy is set to 'Monitor' mode, it only generates alerts and does not enforce any blocking action. To actually block unsanctioned cloud storage apps, the policy must be configured with a 'Block' action type, typically in conjunction with a 'Governance' action that applies the block at the proxy or API level. The 'Monitor' mode is designed for detection and logging, not enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The action type 'Block' is incorrect; it should be 'Alert'
Why it's wrong here
'Block' is indeed a legitimate action type in Microsoft Defender for Cloud Apps policies; you can choose to block access to unsanctioned apps as a governance action. The problem is not the action type itself, but the policy mode being set to 'Monitor', which means the Block action will never be executed—the policy will only generate alerts. Therefore, this statement is incorrect because Block is a valid choice, and the real issue lies elsewhere, specifically in the enforcement mode.
- ✗
The policy requires a 'Device' filter to apply to all users
Why it's wrong here
A 'Device' filter is not necessary for a cloud app policy that applies to all users. In Defender for Cloud Apps, you can scope a policy by user, group, IP address, or app tags, and if you want it to affect everyone, you simply leave filters empty or use 'All users'. Device filters are more relevant to conditional access or session control policies, not to a straightforward app blocking policy. Hence, this is not a requirement for the policy to work, and it is not the reason the policy fails to block.
- ✗
The filter uses 'Unsanctioned' tag, but apps are tagged 'Sanctioned'
Why it's wrong here
The filter using the 'Unsanctioned' tag is actually correct if the apps you intend to target are unsanctioned—that is exactly what the tag is designed for. The statement claims the apps are tagged 'Sanctioned', which would contradict the filter, but if the admin is trying to block unsanctioned apps, the filter is appropriate. The mere presence of the 'Unsanctioned' filter is not the problem; the problem is the policy mode. Thus, this option is incorrect because the filter is valid for the intended scope.
- ✓
The policy mode is set to 'Monitor', which only alerts and does not block
Why this is correct
The policy mode is indeed set to 'Monitor', which is why the 'Block' action does not work. In Defender for Cloud Apps, a policy in Monitor mode only records activity and creates alerts; it does not enforce any governance or blocking actions. To actually block app access, the policy mode must be set to an enforcement mode like 'Block' or 'Govern'. Therefore, this is the correct explanation because changing the mode from Monitor to an enforced setting is required for the Block action to take effect.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.