Courseiva

SC-200 Manage a security operations environment Practice Question

You are configuring Microsoft Defender for Cloud Apps to enhance visibility into your organization's SaaS app usage. You need to ensure that risky user activities are automatically suspended. What should you configure?

⚠ Common exam trap

Test-takers frequently confuse 'session policies' (which control real-time risky activities) with 'app discovery policies' (which only identify shadow IT) or 'file policies' (which protect data, not user behavior), leading them to select a wrong answer that addresses a different security objective.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a session policy to block or limit activities based on risk.

Session policies in Microsoft Defender for Cloud Apps allow you to monitor and control user activities in real time based on risk level. By configuring a session policy with the 'block' or 'limit' action triggered by risk factors (e.g., anomalous location, impossible travel), you can automatically suspend risky user activities without disrupting legitimate usage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set up IP address range policies.

    Why it's wrong here

    IP address range policies are used to mark specific source networks as trusted or untrusted, enabling location-based conditional access decisions and risk scoring for sign-in events. They act at the network origin level, not the application activity level, so they cannot evaluate or restrict individual user actions such as a download or delete within an established session. To control what a user can actually do in a cloud app, you need a session policy that inspects and intervenes on specific activities in real time.

  • ✗

    Configure app discovery policies.

    Why it's wrong here

    App discovery policies analyze cloud traffic logs to identify unsanctioned apps, shadow IT, and calculate a risk score based on app store metadata, traffic volume, and user counts. They help you decide whether to allow or block an entire app, but they do not provide granular control over a user's activities inside a sanctioned app session. App discovery is about which apps are used, not about how a user behaves within an approved application session.

  • ✓

    Create a session policy to block or limit activities based on risk.

    Why this is correct

    Session policies in Microsoft Defender for Cloud Apps use reverse proxy conditional access app control to intercept user sessions in real time, allowing you to allow or block specific activities such as downloading sensitive files, copying data, or uploading from risky devices. They can enforce restrictions based on user risk, device compliance, and contextual signals, applying controls dynamically during the active session. This granular, per-activity enforcement is exactly what is needed to 'block or limit activities based on risk' in a real-time manner.

  • ✗

    Define file policies to protect sensitive data.

    Why it's wrong here

    File policies are content-based rules that scan files stored in cloud apps for sensitive data patterns, such as credit card numbers or personally identifiable information, and can apply actions like file quarantine, user notification, or sharing removal. They operate on files at rest or after an upload, making them reactive and storage-focused, not designed to intercept or block a user's immediate session activities. Unlike session policies, file policies do not look at the context of the user's current interaction or risk signals from the session.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.