Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Your organization has a Microsoft 365 E5 tenant with Microsoft Defender for Cloud Apps. You need to discover and control the use of unsanctioned cloud apps. Which TWO actions should you take? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse Conditional Access policies with the ability to block unsanctioned apps, but Conditional Access requires the app to be registered in Entra ID and cannot discover or block apps that are not already known to the tenant.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define sanctioned and unsanctioned app categories in Microsoft Defender for Cloud Apps

Option D is correct because Cloud Discovery in Microsoft Defender for Cloud Apps is the feature that ingests and analyzes traffic logs (from firewalls, proxies, or Defender for Endpoint) to identify which cloud apps are being used in the organization, which is the required first step for discovering unsanctioned apps. Option A is correct because after discovery, you use the app catalog to tag apps as Sanctioned or Unsanctioned (and assign categories/risk scores), which is how Defender for Cloud Apps enforces the governance decision and drives downstream controls like blocking or alerting. Option B is not correct because Microsoft Purview DLP policies protect sensitive data in sanctioned workloads; they do not discover or sanction/unsanction cloud apps. Option C is not correct because Entra ID App Registrations are for registering and permissioning your own applications with the identity platform, not for logging or discovering third-party cloud app usage. Option E is not correct because Conditional Access cannot target 'all unsanctioned apps' generically; enforcement against unsanctioned apps is done via Defender for Cloud Apps app governance and Conditional Access App Control (session/access policies) after apps are tagged, not by a blanket CA policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Define sanctioned and unsanctioned app categories in Microsoft Defender for Cloud Apps

    Why this is correct

    Sanctioned and unsanctioned app tags let Defender for Cloud Apps apply governance actions such as blocking or unsanctioning, converting discovery data into enforcement. Without these categories, discovered apps cannot be controlled, which the scenario explicitly requires.

  • ✗

    Deploy Microsoft Purview Data Loss Prevention policies

    Why it's wrong here

    Purview DLP policies protect sensitive data within Microsoft 365 workloads; they do not discover shadow IT or govern third-party SaaS usage. Defender for Cloud Apps Cloud Discovery and its app catalogue perform that. DLP would be correct for preventing sensitive content leaving Exchange, SharePoint or Teams.

  • ✗

    Configure Microsoft Entra ID App Registrations to log app usage

    Why it's wrong here

    App registrations define identity and permissions for applications you build or integrate, and they log nothing about unsanctioned third-party usage. Defender for Cloud Apps discovers apps through Cloud Discovery log parsing and its app catalogue. App registrations suit custom apps needing Microsoft Entra ID authentication.

  • ✓

    Use Cloud Discovery in Microsoft Defender for Cloud Apps to analyze traffic logs

    Why this is correct

    Cloud Discovery parses firewall and proxy traffic logs to build an app catalogue with risk scores, providing the visibility needed to identify shadow IT. This satisfies the discovery half of the requirement before any control actions can be applied.

  • ✗

    Create a Conditional Access policy to block all unsanctioned apps

    Why it's wrong here

    Conditional Access governs access to your own tenant resources, not third-party cloud apps, and cannot block apps Defender for Cloud Apps has not sanctioned. Cloud Discovery and app governance handle that. Conditional Access would be correct for restricting sign-ins to your organisation's applications.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.