Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRHard

A security engineer is configuring Microsoft Defender for Cloud Apps (MDCAS) to enforce strict data governance policies. They need to ensure that when users access a specific sanctioned cloud storage application (e.g., SharePoint Online), they are prevented from downloading files containing sensitive data (e.g., personally identifiable information - PII) to unmanaged devices. This restriction should apply only during active user sessions. Which MDCAS policy type, configured with the correct action, will achieve this?

  1. ACloud Discovery anomaly detection policy
  2. BActivity policy with a 'Block' action
  3. CSession policy with a 'Block download' action
  4. DFile policy with a 'Protect' action
Show answer & explanation

Correct answer: C. Session policy with a 'Block download' action

Session policies in MDCAS are specifically designed to monitor and control user activities within a cloud application *in real-time* during a session. By configuring a session policy to detect sensitive data downloads and applying a 'Block download' action when the device is unmanaged, the engineer can prevent data exfiltration as required.

Why the other options are wrong

  • A. Cloud Discovery policies identify shadow IT and assess risk, not enforce real-time data governance during sanctioned app sessions.
  • B. Activity policies detect and act on specific activities (e.g., login from unusual country), but session policies offer more granular, real-time control over downloads during an active session.
  • D. File policies apply to files at rest or during sharing, not real-time session downloads to unmanaged devices.

MDCAS Session Policy: Block Download

A Microsoft Defender for Cloud Apps Session Policy enables real-time monitoring and control over user activities within sanctioned cloud applications, allowing actions like blocking downloads of sensitive data to unmanaged devices.

  • Enforces control during active user sessions.
  • Can detect sensitive information in content.
  • Supports 'Block download' for data exfiltration prevention.

Memory trick: Session policies are like a real-time customs agent, checking every download during a user's cloud 'trip'.

More Mitigate threats using Microsoft Defender XDR questions