Microsoft 365 Administrator Expert MS-102 Practice Question

Your company uses Microsoft Defender for Cloud Apps and has enabled Continuous Report Export through Cloud Discovery. After analyzing the Cloud Discovery dashboard, you identify a high-risk cloud storage service that hosts sensitive data and must be immediately blocked on all corporate Windows 10/11 devices managed by Microsoft Defender for Endpoint (MDE).

You already marked the application as Unsanctioned in Defender for Cloud Apps.

Which additional action should you take to ensure that access to the unsanctioned application is automatically blocked from the managed devices within the next hour?

  • Create a Cloud Discovery activity policy that triggers an automatic governance action to suspend the application.

  • Enable the Block unsanctioned apps setting in the Microsoft 365 Defender portal so that Microsoft Defender for Endpoint can retrieve the updated unsanctioned app list.

  • Configure a Conditional Access App Control session policy that blocks downloads from the application.

  • Add the application's domains to the Endpoint DLP blocked URL list and publish the policy to all devices.

Microsoft 365 Administrator Expert MS-102
Manage security and threats by using Microsoft Defender XDR
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot