SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization uses Microsoft Intune for mobile device management. You need to ensure that users cannot copy corporate data from managed apps to personal apps. Which policy should you configure?
⚠ Common exam trap
Watch out — candidates often confuse App Protection Policies with Device Compliance Policies, thinking that device-level controls can prevent app data leakage, but APP is the only policy that operates at the application layer to enforce data transfer restrictions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
App Protection Policy
App Protection Policies (APP) in Microsoft Intune are designed to manage how data is handled within applications, regardless of device enrollment. By configuring a 'Save as' or 'Copy/paste' restriction between managed and unmanaged apps, you can prevent corporate data from being transferred to personal apps. This policy operates at the app layer, not the device layer, making it the correct choice for this data leakage scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
App Configuration Policy
Why it's wrong here
App Configuration Policies are primarily used to deploy specific settings and configurations to applications, such as pre-populating server URLs, enabling/disabling features, or customizing the user experience within the app itself. While they manage the operational parameters of an application, they do not provide data loss prevention (DLP) controls to restrict actions like copy/paste, "save as," or "open in" functionality between managed and unmanaged applications. Therefore, they cannot prevent sensitive data from leaving the secure app context.
- ✓
App Protection Policy
Why this is correct
App Protection Policies (APP), also known as Mobile Application Management (MAM) policies, are specifically designed to protect organizational data within applications, irrespective of whether the device is enrolled in MDM. These policies enforce granular data loss prevention (DLP) controls, such as restricting copy/paste, preventing "save as" to personal storage locations, or blocking "open in" functionality to unmanaged applications. By creating a secure container around corporate data within compliant apps, APP ensures sensitive information remains within the organization's control, preventing its transfer to personal or unapproved applications.
- ✗
Device Compliance Policy
Why it's wrong here
Device Compliance Policies define the security posture and health requirements that a mobile device must meet to be considered compliant with organizational standards. These policies assess device-level conditions such as OS version, encryption status, PIN requirements, or the presence of jailbreak/root detection. While a non-compliant device might be blocked from accessing corporate resources, these policies do not directly control data movement *between applications* on a compliant device; their focus is on the device's overall state rather than granular app-level data protection.
- ✗
Conditional Access Policy
Why it's wrong here
Conditional Access Policies control *who* can access *what* resources under *what conditions*, evaluating signals like user location, device state, application, and sign-in risk to grant or block access, or to enforce additional requirements like multi-factor authentication. While Conditional Access can block access to an application if specific conditions are not met, it does not govern data transfer *within* an application or *between* applications once access has been granted. Its primary scope is authentication and authorization, not post-access data handling or data loss prevention.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Mobile device management
Mobile device management (MDM) is a security solution that allows IT administrators to enroll, configure, monitor, and enforce policies on smartphones, tablets, and other mobile devices used in an organization.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.