SC-200 Session policy Practice Question
Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud Apps. You receive a high-severity incident indicating that a user's credentials were used to access a sensitive SharePoint site from an unmanaged device. The user, 'jdoe@contoso.com', is a senior executive. The IP address is from a public Wi-Fi hotspot. The incident includes a recommendation to apply session policy to block download of sensitive files. You need to create a policy in Microsoft Defender for Cloud Apps that blocks downloads from unmanaged devices for this specific user when accessing the sensitive site. The policy should trigger only when the user accesses the specific SharePoint site named 'ExecConfidential'. What should you do?
⚠ Common exam trap
The trap is choosing Conditional Access or Intune because they sound like the 'access control' answer, when the requirement is specifically session-level download blocking scoped to a site—a capability only Defender for Cloud Apps session policies provide.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an app connector for SharePoint and a session policy that targets the user, site, and device tag 'Unmanaged' with the action 'Block download'.
Blocking downloads from unmanaged devices for a specific user and site requires a Defender for Cloud Apps session policy, which is enforced through Conditional Access app control and requires the SharePoint app connector to be configured. The session policy can be scoped to the user, the specific site 'ExecConfidential', and the 'Unmanaged' device tag, with the action set to block download. This is the only option that combines the app connector, session control, and the precise scoping the requirement demands.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an app connector for SharePoint and a session policy that targets the user, site, and device tag 'Unmanaged' with the action 'Block download'.
Why this is correct
A SharePoint app connector enables Defender for Cloud Apps to proxy sessions, and a session policy scoped to jdoe, the ExecConfidential site and the Unmanaged device tag applies Block download in real time, satisfying the requirement to prevent sensitive file downloads from unmanaged devices.
- ✗
Create a device compliance policy in Microsoft Intune to block unmanaged devices from accessing SharePoint.
Why it's wrong here
Intune compliance policies only evaluate device state and mark devices compliant or not; they do not inspect SharePoint sessions or block downloads for a named user on a named site. They would be correct where enrolment and device health attestation, not per-session download control, is the requirement.
- ✗
Create a Conditional Access policy in Microsoft Entra ID to require compliant device for the SharePoint site.
Why it's wrong here
Conditional Access enforces compliant-device or MFA gates at authentication, so it cannot block a download mid-session on a specific SharePoint site. It is tempting because it governs unmanaged-device access broadly, and would be correct if the requirement were to deny access entirely rather than block file downloads.
- ✗
Create a file policy in Defender for Cloud Apps to quarantine files downloaded from the site.
Why it's wrong here
A file policy quarantines or governs files already in SharePoint or OneDrive by classification, acting after the fact rather than blocking the download in the user's live session. It would be correct if the aim were to remediate stored sensitive content, not to prevent an unmanaged device retrieving it.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.