
Explanation:
Box 1: Conditional Access
Conditional Access in Microsoft Entra (formerly Azure AD) is the correct mechanism for enforcing multi-factor authentication (MFA) based on specific conditions, such as accessing App1 when sensitive documents are involved. Conditional Access policies can enforce MFA based on user risk, location, or the sensitivity of the data being accessed.
Box 2: Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps allows you to implement session control policies that monitor and control user sessions in real time. It can enforce policies such as blocking downloads of sensitive documents or enforcing additional authentication measures during specific activities within the session.