SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Cloud Apps. You need to block downloads from unmanaged devices for a specific cloud app. What should you configure?
⚠ Common exam trap
Candidates often confuse session policies (real-time proxy control) with file policies (data-at-rest governance) or anomaly detection (behavioral alerts), failing to recognize that device tag conditions are exclusive to session policies for conditional access on unmanaged devices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a session policy with device tag condition.
Session policies in Microsoft Defender for Cloud Apps allow you to control user activities in real time based on device tags. By configuring a session policy with a device tag condition (e.g., 'Device tag equals Unmanaged'), you can enforce actions like blocking downloads from unmanaged devices for a specific cloud app, leveraging reverse proxy architecture to inspect and control traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a file policy with a governance action.
Why it's wrong here
A file policy with a governance action is designed for data classification and protection by inspecting file content, metadata, and sharing permissions. Governance actions such as applying sensitivity labels, revoking external sharing, or quarantining files are reactive and operate on files already stored in the cloud. They cannot enforce real-time controls on user sessions, such as blocking a download from an unmanaged device, because they lack the contextual awareness of the user's device and the session-level inline enforcement required for this scenario.
- ✓
Create a session policy with device tag condition.
Why this is correct
This is correct because Defender for Cloud Apps session policies leverage conditional access app control to enforce real-time session restrictions based on contextual conditions like device tags. By configuring a condition that targets unmanaged devices (using the device tag), the policy can explicitly block or warn on downloads within the user's active browser session. This works by routing the session through the reversing proxy in Defender for Cloud Apps, which inspects and controls actions such as file downloads, uploads, and copy/paste before they reach the user's endpoint.
- ✗
Create an app permissions policy.
Why it's wrong here
An app permissions policy in Defender for Cloud Apps governs the risk associated with OAuth applications that request access to organizational data. It allows you to review and manage third-party app permissions, such as revoking an app's access to Microsoft 365 resources, and is focused on the app-to-data relationship rather than user actions. This policy cannot control user-initiated downloads from unmanaged devices because it operates at the application permission level, not at the user session level, and has no mechanism to contextualize the device or user's current action.
- ✗
Create an anomaly detection policy.
Why it's wrong here
An anomaly detection policy is built to identify suspicious behavior patterns, such as impossible travel, mass downloads, or ransomware activity, after the fact. While these policies trigger alerts and can apply governance actions like suspending a user or isolating an account, they do not proactively block downloads in real time based on a device condition. They are detection-centric, not prevention-centric, and therefore do not meet the requirement to stop downloads from unmanaged devices as the user attempts them.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.