SC-200 Manage a security operations environment Practice Question
Your company uses Microsoft Defender for Cloud Apps to monitor cloud applications. You have discovered that a user is accessing a sanctioned cloud storage app from an IP address that belongs to a known malicious botnet. You need to automatically block the user's access to the app and require them to re-authenticate. You have already configured session policies in Defender for Cloud Apps. What should you do next?
⚠ Common exam trap
Many exam-takers confuse session policies with access policies; access policies only block or allow at the app level without session-level controls like re-authentication, while session policies provide the granular, real-time actions needed for this scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a session policy in Defender for Cloud Apps with the action 'Block' and 'Require re-authentication'.
Session policies in Defender for Cloud Apps can enforce real-time controls on sanctioned apps. By configuring a session policy with the actions 'Block' and 'Require re-authentication', you can immediately terminate the user's session and force them to re-authenticate, which effectively blocks access from the malicious IP while ensuring the user re-verifies their identity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an access policy in Defender for Cloud Apps to block the user.
Why it's wrong here
Access policies in Defender for Cloud Apps are evaluated as conditional access policies at the initial sign-in, and while they can block a user's access, they cannot force a re-authentication within an ongoing session. The requirement explicitly asks for both a block and a re-authentication action, which is only available through a session policy that uses Conditional Access App Control to intercept and control traffic in real time. Therefore, an access policy alone is insufficient because it lacks the 'Require re-authentication' action and cannot respond mid-session.
- ✗
Create an app governance policy in Microsoft Purview to block the app.
Why it's wrong here
App governance policies in Microsoft Purview are designed for monitoring and governing the behavior of third-party and first-party apps, including compliance assessments and alerting on suspicious app activities. They do not enforce real-time access control or session-level actions such as blocking a user or forcing re-authentication; instead, they operate on app risk signals and may generate alerts or recommendations. Thus, this option is wrong because it addresses app oversight rather than real-time user session enforcement.
- ✓
Configure a session policy in Defender for Cloud Apps with the action 'Block' and 'Require re-authentication'.
Why this is correct
A session policy in Defender for Cloud Apps, when combined with Conditional Access App Control, can inspect and control app sessions in real time using a reverse proxy. Setting the action to 'Block' and 'Require re-authentication' immediately terminates the current session and forces the user to sign in again, thereby meeting the requirement of both blocking access and enforcing fresh authentication. This is the only option that provides both capabilities together, distinguishing it from access policies that lack the re-authentication action.
- ✗
Create a device compliance policy in Microsoft Intune to block the device.
Why it's wrong here
Device compliance policies in Microsoft Intune evaluate the health and configuration of devices and provide a compliance status that can be used by Conditional Access, but they do not perform real-time blocking within a cloud app session. Such policies cannot force a user to re-authenticate when a session needs to be terminated due to risk; they only influence access decisions during the initial sign-in process. Therefore, this option is incorrect because it operates at a device-level pre-access stage, not as a real-time session control.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.