Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Defender for Cloud Apps. You detect a suspicious app that has high data access and unusual API calls. You want to automatically block the app and notify the user. What should you implement?

⚠ Common exam trap

It's easy for candidates to confuse 'blocking an app' (which requires an app governance policy) with 'blocking user access to an app' (which is done via an access policy), leading them to choose the access policy option even though it does not block the app itself or notify the user.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an app governance policy that automatically blocks the app and sends a notification to the user.

App governance policies in Microsoft Defender for Cloud Apps are specifically designed to govern OAuth-enabled apps that have been granted permissions to access organizational data. When an app exhibits suspicious behavior like high data access and unusual API calls, an app governance policy can automatically block the app and send a notification to the user, directly addressing the requirement to both block and notify.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an access policy that blocks the app based on the risk level.

    Why it's wrong here

    An access policy in Microsoft Defender for Cloud Apps evaluates user, device, and location risk to either allow or block a user's session to an app. It does not block the app itself or alter its availability within your tenant; it only prevents the user from establishing a session. Thus, while it can restrict access based on risk, it is not the correct mechanism to automatically block the app and notify the user.

  • ✓

    Create an app governance policy that automatically blocks the app and sends a notification to the user.

    Why this is correct

    App governance policies in Defender for Cloud Apps are specifically designed to govern OAuth apps and can perform automated actions such as disabling or blocking an app when suspicious behavior is detected. When a policy triggers, it can block the app from accessing resources and send notification emails to the configured recipients, including the user or admin. This directly matches the stated requirement, making it the correct choice.

  • ✗

    Create a session policy to monitor the app's API calls.

    Why it's wrong here

    A session policy in Defender for Cloud Apps uses Conditional Access App Control to monitor and control real-time user actions within a session, including API calls if configured. It works by redirecting traffic through a reverse proxy to apply granular controls like blocking file downloads or requiring step-up authentication, but it cannot block the application itself from functioning. Therefore, it is unsuitable for automatically blocking the app and notifying the user.

  • ✗

    Create a DLP policy to prevent data exfiltration from the app.

    Why it's wrong here

    DLP (Data Loss Prevention) policies in Defender for Cloud Apps are focused on scanning and protecting sensitive content in transit or at rest, preventing actions like sharing or copying data outside authorized boundaries. They can block a specific operation (e.g., emailing a credit card number) but they do not block the entire application or prevent the app from running. Hence, this option addresses data exfiltration, not app blocking, so it is incorrect.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.