exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 3 question 22 discussion

Actual exam question from Microsoft's MS-500
Question #: 22
Topic #: 3
[All MS-500 Questions]

You have a Microsoft 365 subscription that includes a user named User1.
You have a conditional access policy that applies to Microsoft Exchange Online. The conditional access policy is configured to use Conditional Access App
Control.
You need to create a Microsoft Cloud App Security policy that blocks User1 from printing from Exchange Online.
Which type of Cloud App Security policy should you create?

  • A. an app permission policy
  • B. an activity policy
  • C. a Cloud Discovery anomaly detection policy
  • D. a session policy
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Vishbsoni
Highly Voted 4 years, 5 months ago
The answer is D: Session Policy Enforce read-only mode for external users in real time Prevent company data from being exfiltrated by external users, by blocking print and copy/paste activities in real-time, utilizing Cloud App Security's session controls. https://docs.microsoft.com/en-us/cloud-app-security/policies-information-protection#enforce-read-only-mode-for-external-users-in-real-time:~:text=.-,Enforce%20read%2Donly%20mode%20for%20external%20users%20in%20real%20time,Prevent%20company%20data%20from%20being%20exfiltrated%20by%20external%20users%2C%20by%20blocking%20print%20and%20copy%2Fpaste%20activities%20in%20real%2Dtime%2C%20utilizing%20Cloud%20App%20Security's%20session%20controls.,-Prerequisites
upvoted 20 times
...
TonySuccess
Highly Voted 4 years, 4 months ago
I tried to test this in Cloud App Security and to be honest as a novice in CAS I was struggling. My results were inconclusive, so I sent Microsft an Email and they replied confirming the given answer is correct. This is completed by creating a Session Control Policy in CAS. Then 'Use Custom Policy' in Conditional Access and select the policy you created in Cloud App Security from the list. x
upvoted 12 times
...
VJO
Most Recent 2 years, 5 months ago
This question is outdated. Microsoft Cloud App was replaced with Microsoft Defender for Cloud Apps. Please remove.
upvoted 1 times
...
cyberknight55
2 years, 7 months ago
Selected Answer: D
Session policy
upvoted 1 times
...
[Removed]
2 years, 7 months ago
Selected Answer: D
Session Policy for sure.
upvoted 1 times
...
Jhill777
3 years, 2 months ago
Selected Answer: D
Session policy
upvoted 2 times
...
mbecile
3 years, 3 months ago
D is indeed the answer. Via Microsoft Docs, there are only two different policies, Access and Session. Access policies will block the ability to use the app at all. Session policies can restrict specific activities when setting the type to "Activity" Source: https://docs.microsoft.com/en-us/defender-cloud-apps/session-policy-aad#block-activities
upvoted 1 times
...
mkoprivnj
3 years, 4 months ago
Selected Answer: D
D is correct!
upvoted 2 times
...
Rstilekar
3 years, 5 months ago
Correct ans. Session policy With the access and session policies, you can: Prevent data exfiltration: You can block the download, cut, copy, and print of sensitive documents on, for example, unmanaged devices. https://docs.microsoft.com/en-us/cloud-app-security/proxy-intro-aad#how-it-works:~:text=With%20the%20access%20and%20session%20policies%2C,documents%20on%2C%20for%20example%2C%20unmanaged%20devices. Session control applies to browser-based apps. To block access from mobile and desktop apps, create an Access policy While Activity Policies are for generating alerts and using Governance action to Suspend users etc. Based on x activity or repeat activities suspend user/confirm user compromised etc.
upvoted 1 times
...
Joshing
3 years, 9 months ago
The correct answer is a Session Policy. You set up a Session policy. Session control type of Block. Put in the filter for the activity of printing and then use the action to block. Activity Policies are for generating alerts and using Governance action to Suspend users etc. Based on x activity or repeat activities suspend user/confirm user compromised etc.
upvoted 2 times
...
TimurKazan
3 years, 12 months ago
I have tested this in lab, it is D- Session Policy
upvoted 3 times
...
Vishbsoni
4 years, 5 months ago
With the access and session policies, you can: Prevent data exfiltration: You can block the download, cut, copy, and print of sensitive documents on, for example, unmanaged devices. https://docs.microsoft.com/en-us/cloud-app-security/proxy-intro-aad#how-it-works:~:text=With%20the%20access%20and%20session%20policies%2C,documents%20on%2C%20for%20example%2C%20unmanaged%20devices.
upvoted 4 times
kiketxu
4 years, 1 month ago
Thanks for the research and highlinting dude! ;)
upvoted 1 times
ellik
4 years ago
Session control applies to browser-based apps. To block access from mobile and desktop apps, create an Access policy
upvoted 1 times
...
...
...
LoFix
4 years, 5 months ago
Why not "Activity policy", we can define there an "Activity type" filter? https://docs.microsoft.com/en-us/cloud-app-security/user-activity-policies
upvoted 1 times
musiman
4 years, 5 months ago
I also think it's B, an activity policy. You cannot select the option to deny printing is a session policy (I can't find it there). So, I would choose answer B.
upvoted 1 times
vishg
4 years, 3 months ago
What is the correct answer?
upvoted 1 times
...
ellik
4 years ago
Session control applies to browser-based apps. To block access from mobile and desktop apps, create an Access policy
upvoted 1 times
...
...
...
Omar89
5 years, 3 months ago
reference: https://docs.microsoft.com/en-us/cloud-app-security/session-policy-aad
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago