Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRHard
A security administrator needs to block specific file types, such as executable files (.exe) and scripts (.ps1), from being downloaded from unsanctioned cloud storage applications identified by Microsoft Defender for Cloud Apps (MDCAS). This policy should apply only when users are accessing these applications from unmanaged devices. Which type of policy in MDCAS should the administrator configure?
- AFile policy
- BAnomaly detection policy
- CSession policy
- DActivity policy
Show answer & explanationAnswer & explanation
Correct answer: C. Session policy
To enforce granular controls like blocking specific file types during downloads, especially when conditions like 'unmanaged device' are involved, a Session policy in MDCAS is required. Session policies provide real-time monitoring and control over user sessions, allowing for actions like blocking downloads based on content inspection.
Why the other options are wrong
- A. File policies apply to files at rest in cloud apps, not real-time download actions during a session.
- B. Anomaly detection policies identify unusual behavior, but don't provide explicit content blocking for specific file types during a download.
- D. Activity policies detect and alert on specific user activities, but do not provide real-time session control to block downloads of specific file types.
MDCAS Session Policy
A policy type in Microsoft Defender for Cloud Apps that enables real-time monitoring and control over user sessions with cloud applications, allowing for granular actions like blocking downloads, uploads, or specific activities based on user, device, and content.
- Operates in real-time during a user session.
- Requires integration with a reverse proxy or conditional access app control.
- Can enforce download/upload restrictions, content inspection, and data protection.
Memory trick: Sessions need real-time supervision.