SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Purview Data Loss Prevention (DLP) and Microsoft Defender for Cloud Apps. During an incident, you discover that a user is exfiltrating sensitive data via a sanctioned cloud app. You need to block the user's ability to share files in that app immediately. What should you do?
⚠ Common exam trap
SC-200 often tests the difference between session policies (real-time, user-scoped, app-level control) and DLP policies (content-based, broader) — candidates pick DLP because it sounds like the data-protection tool, but the scenario demands immediate user-level blocking in a sanctioned app.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a session policy in Microsoft Defender for Cloud Apps to block the user's file sharing activity.
To immediately block a user's file-sharing activity in a sanctioned cloud app, create a session policy in Microsoft Defender for Cloud Apps. Session policies use Conditional Access App Control to proxy the session and apply real-time controls such as block download, block upload, or block sharing for specific users or groups. This is the fastest, most targeted control for the described scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a session policy in Microsoft Defender for Cloud Apps to block the user's file sharing activity.
Why this is correct
Session policies in Defender for Cloud Apps proxy the sanctioned app's traffic, allowing real-time control actions such as blocking file sharing for a specific user. This satisfies the requirement to stop exfiltration immediately without revoking the app's sanctioned status.
- ✗
Disable the app connector for that cloud app in Microsoft Defender for Cloud Apps.
Why it's wrong here
Disabling the app connector halts API traffic for every user of that cloud app, not just the exfiltrating user, so it is not a targeted immediate block. It is tempting when the app itself is untrusted or compromised, but here the app is sanctioned and only one user's sharing must be stopped.
- ✗
Remove the user from the Microsoft Entra ID group that allows access to the cloud app.
Why it's wrong here
Removing group membership revokes the user's access to the app entirely rather than blocking file sharing within it, and group changes may not apply instantly. It is tempting as coarse containment for a compromised account, but the requirement is to stop sharing while the sanctioned app remains usable.
- ✗
Create a Microsoft Purview DLP policy to block sharing of sensitive content.
Why it's wrong here
Microsoft Purview DLP policies are designed for proactive content-based prevention, identifying and blocking sensitive data sharing across services like Exchange and SharePoint. This option fails because it does not provide the immediate, app-level user activity control required to block file sharing within a sanctioned cloud app during an active exfiltration incident. It is tempting as DLP does block sharing, and it is the correct choice for establishing content-aware policies to prevent sensitive data from being shared inappropriately across your Microsoft 365 ecosystem.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.