Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

You have a Microsoft 365 E5 tenant with Microsoft Defender for Cloud Apps. You need to discover unsanctioned cloud apps used by users. What should you configure?

⚠ Common exam trap

Watch out — candidates often confuse Conditional Access App Control (a policy enforcement mechanism for sanctioned apps) with Cloud Discovery (the actual discovery and risk assessment feature), leading them to select Option A instead of the correct answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Cloud Apps Cloud Discovery

Microsoft Defender for Cloud Apps Cloud Discovery is the correct feature for identifying unsanctioned cloud apps used in your environment. It analyzes traffic logs from your network or endpoints to discover all cloud app usage, categorizes them by risk, and allows you to sanction or unsanction them. This directly fulfills the requirement to discover unsanctioned cloud apps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conditional Access App Control

    Why it's wrong here

    Conditional Access App Control (CAAC) is a feature of Microsoft Defender for Cloud Apps that provides real-time session monitoring and control through a reverse proxy, enforcing policies on sanctioned SaaS apps. It does not identify unknown or unsanctioned applications; it only operates on apps already known to the tenant. Therefore, it cannot perform discovery or inventory of cloud app usage.

  • ✗

    Microsoft Purview Data Loss Prevention

    Why it's wrong here

    Microsoft Purview Data Loss Prevention (DLP) inspects sensitive data across Exchange, SharePoint, OneDrive, and endpoints, then applies actions like blocking, encryption, or user notifications. Its policy engine is designed to protect content, not to analyze network traffic or produce an inventory of third-party cloud apps. Consequently, DLP cannot reveal which unsanctioned apps are being used by your users.

  • ✗

    Microsoft Defender for Endpoint App Control

    Why it's wrong here

    Microsoft Defender for Endpoint App Control (also known as Windows Defender Application Control) uses code integrity policies to restrict which executables, drivers, and scripts are allowed to run on managed endpoints. It is a host-based execution control mechanism, not a network-level or SaaS-usage discovery tool. Thus it provides no visibility into cloud app usage or shadow IT inventory.

  • ✓

    Microsoft Defender for Cloud Apps Cloud Discovery

    Why this is correct

    Microsoft Defender for Cloud Apps Cloud Discovery parses your network traffic logs, either uploaded manually or forwarded via integrated proxies and Defender for Endpoint, to identify and score the cloud apps your users access. It compares traffic against a catalog of over 31,000 apps and even detects unknown apps heuristically, enabling you to mark them as sanctioned or unsanctioned. This is the correct tool for discovering the full landscape of apps in your environment.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.