Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Purview Data Loss Prevention (DLP) and Microsoft Defender for Cloud Apps. During an incident, you discover that a user is exfiltrating sensitive data via a sanctioned cloud app. You need to block the user's ability to share files in that app immediately. What should you do?

⚠ Common exam trap

SC-200 often tests the difference between session policies (real-time, user-scoped, app-level control) and DLP policies (content-based, broader) — candidates pick DLP because it sounds like the data-protection tool, but the scenario demands immediate user-level blocking in a sanctioned app.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a session policy in Microsoft Defender for Cloud Apps to block the user's file sharing activity.

To immediately block a user's file-sharing activity in a sanctioned cloud app, create a session policy in Microsoft Defender for Cloud Apps. Session policies use Conditional Access App Control to proxy the session and apply real-time controls such as block download, block upload, or block sharing for specific users or groups. This is the fastest, most targeted control for the described scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a session policy in Microsoft Defender for Cloud Apps to block the user's file sharing activity.

    Why this is correct

    Session policies in Defender for Cloud Apps proxy the sanctioned app's traffic, allowing real-time control actions such as blocking file sharing for a specific user. This satisfies the requirement to stop exfiltration immediately without revoking the app's sanctioned status.

  • ✗

    Disable the app connector for that cloud app in Microsoft Defender for Cloud Apps.

    Why it's wrong here

    Disabling the app connector halts API traffic for every user of that cloud app, not just the exfiltrating user, so it is not a targeted immediate block. It is tempting when the app itself is untrusted or compromised, but here the app is sanctioned and only one user's sharing must be stopped.

  • ✗

    Remove the user from the Microsoft Entra ID group that allows access to the cloud app.

    Why it's wrong here

    Removing group membership revokes the user's access to the app entirely rather than blocking file sharing within it, and group changes may not apply instantly. It is tempting as coarse containment for a compromised account, but the requirement is to stop sharing while the sanctioned app remains usable.

  • ✗

    Create a Microsoft Purview DLP policy to block sharing of sensitive content.

    Why it's wrong here

    Microsoft Purview DLP policies are designed for proactive content-based prevention, identifying and blocking sensitive data sharing across services like Exchange and SharePoint. This option fails because it does not provide the immediate, app-level user activity control required to block file sharing within a sanctioned cloud app during an active exfiltration incident. It is tempting as DLP does block sharing, and it is the correct choice for establishing content-aware policies to prevent sensitive data from being shared inappropriately across your Microsoft 365 ecosystem.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.