SC-300 Exam QuestionsBrowse all questions from this exam

SC-300 Exam - Question 233


You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps and Conditional Access policies.

You need to block access to cloud apps when a user is assessed as high risk.

Which type of policy should you create in the Microsoft Defender for Cloud Apps portal?

Show Answer
Correct Answer: A

To block access to cloud apps when a user is assessed as high risk, the appropriate type of policy to create in the Microsoft Defender for Cloud Apps portal is an access policy. Access policies in Microsoft Defender for Cloud Apps provide real-time monitoring and control over access to cloud applications based on various factors such as user, location, device, and app. This allows you to enforce security measures like blocking access under certain risk conditions, which aligns with the requirement provided in the question.

Discussion

8 comments
Sign in to comment
Zak366Option: A
Feb 23, 2023

Correct. A Microsoft Defender for Cloud Apps access policies enable real-time monitoring and control over access to cloud apps based on user, location, device, and app. https://learn.microsoft.com/en-us/defender-cloud-apps/access-policy-aad

mohsanarfandanishOption: A
Apr 1, 2023

Sign in to the Microsoft Defender for Cloud Apps portal. Click on the Access policies tab. Click Create policy.

mohsanarfandanish
Mar 30, 2023

Correct is A

dule27Option: A
Jun 19, 2023

A. access policy

EmnCoursOption: A
Aug 15, 2023

A. access policy

Discuss4certiOption: C
Jul 4, 2024

bruh sheeple here in the comment section. Does anyone ever really look for the answer: Anomaly detection policies enable you to look for unusual activities on your cloud. Detection is based on the risk factors you set to alert you when something happens that is different from the baseline of your organization or from the user's regular activity

Labelfree
Nov 21, 2024

Anomaly detection doesn't "block" access, as the question is asking. It only generates reports.

armid
Feb 22, 2025

the only reason why i will choose A is because "uses MS Defender for Cloud Apps AND CONDITIONAL ACCESS POLICIES" otherwise anomaly detection policy would suit better, and yes it can block users based on user risk in the Governance Actions section however anomaly detection policies dont really work with conditional access as far as i understand

armid
Feb 22, 2025

the only reason why i will choose A is because "uses MS Defender for Cloud Apps AND CONDITIONAL ACCESS POLICIES" otherwise anomaly detection policy would suit better, and yes it can block users based on user risk in the Governance Actions section however anomaly detection policies dont really work with conditional access as far as i understand

Obi_Wan_Jacoby
Apr 15, 2025

Looks like answer A is it. While anomaly detection policies can include governance actions like suspending users or requiring password changes, they don't inherently block access to cloud apps based on user risk. For directly blocking access when a user is assessed as high risk, an access policy is more suitable because it allows you to enforce real-time access controls based on user risk levels.

Panama469Option: A
Jul 7, 2024

A. The App Control policy you create as a prerequisite for a cloud app access policy can configured with the risk policies (Identity Protection) with the user risk set to 'high' and access control set to block instead of grant.

Panama469
Jul 7, 2024

Sorry the Conditional Access Policy (App Control policy) you create as a prerequisite...

Obi_Wan_JacobyOption: A
Apr 15, 2025

A. access policy: While anomaly detection policies can include governance actions like suspending users or requiring password changes, they don't inherently block access to cloud apps based on user risk1. For directly blocking access when a user is assessed as high risk, an access policy is more suitable because it allows you to enforce real-time access controls based on user risk levels2.