MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Which TWO are key capabilities of Microsoft Defender for Cloud Apps? (Choose two.)
⚠ Common exam trap
MS-900 often tests the distinction between Defender for Cloud Apps and other Microsoft security services; candidates might confuse email encryption (Purview) or device compliance (Intune) as features of Defender for Cloud Apps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Discovery to identify shadow IT
Option D (Cloud Discovery to identify shadow IT) is correct because Defender for Cloud Apps uses Cloud Discovery to analyze traffic logs from firewalls and proxies (or via the Defender for Endpoint integration) to detect unsanctioned SaaS apps, giving organizations visibility into shadow IT. Option E (Session control to monitor and control app access in real-time) is correct because Conditional Access App Control uses a reverse proxy to enforce real-time session policies, such as blocking downloads or uploads, on cloud apps. Option A is incorrect because email encryption and secure messaging are capabilities of Microsoft Purview (Exchange Online/Message Encryption), not Defender for Cloud Apps. Option B is incorrect because device compliance policy enforcement is handled by Microsoft Intune and Conditional Access, not Defender for Cloud Apps. Option C is incorrect because on-device malware scanning is provided by Microsoft Defender for Endpoint, not Defender for Cloud Apps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Email encryption and secure messaging
Why it's wrong here
Defender for Cloud Apps delivers shadow IT discovery, cloud app risk assessment, anomaly detection, and information protection across sanctioned and unsanctioned SaaS. Email encryption and secure messaging belong to Exchange Online and Microsoft Purview, which suit protecting mail content in transit rather than governing cloud app usage.
- ✗
Device compliance policy enforcement
Why it's wrong here
Device compliance policy enforcement is handled by Microsoft Intune, which evaluates device state against configuration baselines and conditional access. Defender for Cloud Apps operates at the cloud-app session layer, applying anomaly detection and data controls rather than endpoint compliance. Shared Defender branding makes the confusion tempting, since both surface alerts in the XDR portal.
- ✗
On-device malware scanning
Why it's wrong here
On-device malware scanning belongs to Microsoft Defender for Endpoint, which inspects local files and processes on enrolled devices. Defender for Cloud Apps instead governs SaaS usage through discovery, session controls and app risk scoring. The option tempts because both products share the Defender branding and feed signals into Microsoft Defender XDR.
- ✓
Cloud Discovery to identify shadow IT
Why this is correct
Cloud Discovery analyses traffic logs from firewalls and proxies to catalogue which cloud apps employees actually use, exposing unsanctioned shadow IT. That visibility is the capability the stem asks for, distinct from session or access controls.
- ✓
Session control to monitor and control app access in real-time
Why this is correct
Session control proxies user sessions to cloud apps in real time, allowing conditional access policies to block downloads, encrypt files or restrict actions mid-session. This is the live monitoring and control capability the stem requires, unlike discovery's retrospective log analysis.
Go deeper
Related to this question
Learn chapter
Windows 365 Cloud PC
Key term
Exchange Online
Exchange Online is Microsoft's cloud-based email, calendar, and contact hosting service that is part of the Microsoft 365 suite, allowing organizations to manage corporate messaging without maintaining their own mail servers.
Key term
Defender for Endpoint
Microsoft Defender for Endpoint is a cloud-delivered enterprise security solution designed to protect devices from cyber threats using behavioral analysis, machine learning, and automated investigation.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.