SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Cloud Apps. You need to block downloads from a specific app for users outside the corporate network. What should you configure?
⚠ Common exam trap
Many exam-takers confuse access policies (which control sign-in) with session policies (which control in-session actions), leading candidates to choose D when they need granular action-level control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A session policy
A session policy in Microsoft Defender for Cloud Apps allows you to monitor and control user activities in real time by leveraging reverse proxy architecture. To block downloads from a specific app for users outside the corporate network, you configure a session policy with the action 'Block' and apply a condition based on the IP address tag (e.g., 'Not corporate IP range'). This enforces the restriction at the moment the user attempts to download, without affecting other app activities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A session policy
Why this is correct
A session policy is correct because it operates in real time using Conditional Access App Control to reverse-proxy user actions, enabling granular controls such as blocking a download based on the user's geolocation. Session policies are the only option here that can intercept and enforce at the individual action level within an active application session, not just at sign-in or post-hoc.
- ✗
An anomaly detection alert
Why it's wrong here
An anomaly detection alert identifies unusual behavioral patterns, such as impossible travel or mass download activity, using machine learning heuristics. However, it is purely detective and generates a notification in Microsoft Defender for Cloud Apps; it cannot actively block a user's action in the moment, so it would not satisfy a requirement to block downloads based on location.
- ✗
A file policy
Why it's wrong here
A file policy is designed for ongoing governance of files already stored in connected apps, evaluating conditions like sharing level, file extension, or DLP classification, and can trigger remediation such as quarantining or removing external sharing. It is not a real-time control for user actions within an app session, and it cannot respond to the user's current geographic location to block an attempted download.
- ✗
An access policy
Why it's wrong here
An access policy evaluates sign-in attempts and controls access by requiring actions like multifactor authentication or blocking the login entirely based on conditions such as location and device compliance. It stops the user from getting in, but it cannot enforce fine-grained restrictions on what the user does after access is granted, such as blocking a download while allowing other activities. Thus it is insufficient for the stated requirement of blocking a download based on location.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.