Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRHard
A security engineer is configuring Microsoft Defender for Cloud Apps (MDCAS) to enforce strict data governance. The organization requires that users are prevented from downloading sensitive financial documents from unapproved cloud storage services, even if they are logged into their corporate accounts. Instead, they should be redirected to an approved service. Which type of policy and associated action in MDCAS should the engineer implement to meet this requirement?
- ASession policy with 'Block download' action and 'Redirect' control
- BActivity policy with 'Alert' action
- CAnomaly detection policy with 'Suspend user' action
- DFile policy with 'Block' action
Show answer & explanationAnswer & explanation
Correct answer: A. Session policy with 'Block download' action and 'Redirect' control
To prevent downloads and redirect, a Session policy is required. This policy type allows real-time monitoring and control over sessions, enabling actions like 'Block download' and crucially, 'Redirect to URL' to guide users to approved services, which is not possible with File or Activity policies.
Why the other options are wrong
- B. An Activity policy can detect and alert on activities, but it cannot prevent a download in real-time or redirect the user.
- C. Anomaly detection policies identify unusual behavior and can suspend users, but they don't provide real-time download prevention or redirection capabilities for specific data governance rules.
- D. A File policy can block access to files based on content, but it cannot redirect the user during a download attempt from a session.
MDCAS Session Policy (Block & Redirect)
A Microsoft Defender for Cloud Apps policy that allows real-time, granular control over user sessions with cloud applications, including blocking specific actions like downloads and redirecting users to alternative URLs.
- Operates in real-time during user sessions.
- Can block downloads of sensitive content.
- Can redirect users to approved services or URLs.
Memory trick: To control a live session, you need a 'session' policy; it's the only one that can redirect.