SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Defender for Cloud Apps. During an incident, you discover that a user is downloading large amounts of data from SharePoint to an unmanaged device. You need to automatically block further downloads from that device. What should you configure?
⚠ Common exam trap
A common mix-up: candidates confuse session policies with Conditional Access or DLP policies, not realizing that only session policies provide real-time, granular control over specific actions like downloads within a cloud app session.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a session policy in Microsoft Defender for Cloud Apps to block download.
A session policy in Microsoft Defender for Cloud Apps uses reverse proxy capabilities to monitor and control user activities in real time. By configuring a session policy with the 'block download' action, you can immediately stop further downloads from SharePoint to the unmanaged device during the incident, without affecting managed devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a session policy in Microsoft Defender for Cloud Apps to block download.
Why this is correct
A session policy in Microsoft Defender for Cloud Apps operates via reverse-proxy conditional access app control, giving you real-time, action-level visibility and enforcement. By setting the 'block download' action alongside other file-related controls, the policy inspects every HTTP transaction and can block a download request while still allowing viewing or other cloud-app activities. This is the only option here that directly targets downloads as a discrete action rather than toggling all-or-nothing access to the application.
- ✗
Create a Conditional Access policy to require a compliant device.
Why it's wrong here
A Conditional Access policy that requires a compliant device is an access-gating control, not an in-session action control. It blocks the entire user session if the device lacks compliance, so you cannot selectively allow a user into the app but prevent the download action. Compliance evaluation happens at sign-on and doesn't evaluate activity inside the app, leaving downloads available to any user who passes the access check.
- ✗
Configure Microsoft Intune device compliance policy.
Why it's wrong here
Microsoft Intune device compliance policies define requirements such as encryption, OS version, PIN, or being a domain-joined device, but they operate purely at the device level. They don't understand or control application-layer primitives like 'download this file' inside a SaaS app. Moreover, these policies apply only to enrolled, managed devices, so they do nothing for unmanaged or visitor access, and they would only feed into Conditional Access as an access decision, not a granular file-action restriction.
- ✗
Create a DLP policy in Microsoft Purview.
Why it's wrong here
A Microsoft Purview DLP policy is focused on preventing data leakage by detecting sensitive content (e.g., credit cards, PII) in email, files, and cloud services, and it typically alerts or blocks based on content matching rules. Even when extended into Defender for Cloud Apps via DLP integration, it is not a session-level engine: it evaluates the file's classification, not the action of downloading, and it cannot selectively block a download while keeping the rest of the session functional. The enforcement endpoint and policy granularity for download interception is session policy, not DLP.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.