MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security administrator needs to discover which cloud apps are being used in the organization and then block usage of unsanctioned apps in real time using a reverse proxy. Which two Microsoft Defender for Cloud Apps features must be configured to meet these requirements? (Select all that apply.)
⚠ Common exam trap
Many exam-takers confuse App Connectors/API connectors (which provide API-based control for specific apps) with the reverse proxy and discovery capabilities of Cloud Discovery and Conditional Access App Control, leading candidates to select options that manage existing apps rather than discover and block unsanctioned ones.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Discovery
Cloud Discovery (A) is correct because it analyzes traffic logs from your network to identify all cloud apps in use, providing visibility into sanctioned and unsanctioned apps. Conditional Access App Control (C) is correct because it enforces real-time access controls via a reverse proxy, allowing you to block unsanctioned apps as users attempt to access them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cloud Discovery
Why this is correct
Cloud Discovery is the Defender for Cloud Apps feature that analyzes traffic logs from enterprise proxies or Microsoft Defender for Endpoint to identify brand-specific cloud app usage across the organization. It continuously monitors shadow IT by discovering applications that users access, then scores them for risk (e.g., security, compliance) to create a catalog of sanctioned and unsanctioned apps. This is the correct first step for understanding 'which cloud apps are being used' — it provides the raw visibility that later enables blocking.
- ✗
App Connectors
Why it's wrong here
App Connectors in Defender for Cloud Apps are API-based integrations configured for specific applications (e.g., Office 365, Salesforce) that require admin credentials in the target app. These connectors pull activities, files, and alerts for that known app, which enables deep control such as suspending a user or quarantining a file, but they cannot discover unknown or unmanaged apps because they only contact the one app you explicitly link. They also do not intercept traffic in real time, so they are not a mechanism for discovering the application footprint in the org.
- ✓
Conditional Access App Control
Why this is correct
Conditional Access App Control is a reverse-proxy capability that works with Microsoft Entra Conditional Access to route selected user sessions through Defender for Cloud Apps. Based on the app's risk profile and policies, it can block sign-in or block actions (e.g., upload, download, copy) for unsanctioned apps in real-time — for example, preventing a user from downloading a file from a newly detected app. It does not perform discovery on its own; rather, it relies on Cloud Discovery to identify which apps are actually in use, and it enforces access decisions after the app is known.
- ✗
API connectors
Why it's wrong here
API connectors, in this context, are essentially the same underlying mechanism as App Connectors — they are the generic term for integrating via an app's API to ingest metadata. They give you API-based visibility into events and user data for the specific connected services, but they cannot identify shadow IT because they only know about apps you've already manually connected. They also lack the reverse-proxy capability required to block traffic in real time, so they neither discover new cloud apps nor enforce session-level access controls on them.
Go deeper
Related to this question
Learn chapter
Intune and Conditional Access Integration
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.