Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Which TWO are key capabilities of Microsoft Defender for Cloud Apps? (Choose two.)

⚠ Common exam trap

MS-900 often tests the distinction between Defender for Cloud Apps and other Microsoft security services; candidates might confuse email encryption (Purview) or device compliance (Intune) as features of Defender for Cloud Apps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Discovery to identify shadow IT

Option D (Cloud Discovery to identify shadow IT) is correct because Defender for Cloud Apps uses Cloud Discovery to analyze traffic logs from firewalls and proxies (or via the Defender for Endpoint integration) to detect unsanctioned SaaS apps, giving organizations visibility into shadow IT. Option E (Session control to monitor and control app access in real-time) is correct because Conditional Access App Control uses a reverse proxy to enforce real-time session policies, such as blocking downloads or uploads, on cloud apps. Option A is incorrect because email encryption and secure messaging are capabilities of Microsoft Purview (Exchange Online/Message Encryption), not Defender for Cloud Apps. Option B is incorrect because device compliance policy enforcement is handled by Microsoft Intune and Conditional Access, not Defender for Cloud Apps. Option C is incorrect because on-device malware scanning is provided by Microsoft Defender for Endpoint, not Defender for Cloud Apps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Email encryption and secure messaging

    Why it's wrong here

    Defender for Cloud Apps delivers shadow IT discovery, cloud app risk assessment, anomaly detection, and information protection across sanctioned and unsanctioned SaaS. Email encryption and secure messaging belong to Exchange Online and Microsoft Purview, which suit protecting mail content in transit rather than governing cloud app usage.

  • ✗

    Device compliance policy enforcement

    Why it's wrong here

    Device compliance policy enforcement is handled by Microsoft Intune, which evaluates device state against configuration baselines and conditional access. Defender for Cloud Apps operates at the cloud-app session layer, applying anomaly detection and data controls rather than endpoint compliance. Shared Defender branding makes the confusion tempting, since both surface alerts in the XDR portal.

  • ✗

    On-device malware scanning

    Why it's wrong here

    On-device malware scanning belongs to Microsoft Defender for Endpoint, which inspects local files and processes on enrolled devices. Defender for Cloud Apps instead governs SaaS usage through discovery, session controls and app risk scoring. The option tempts because both products share the Defender branding and feed signals into Microsoft Defender XDR.

  • ✓

    Cloud Discovery to identify shadow IT

    Why this is correct

    Cloud Discovery analyses traffic logs from firewalls and proxies to catalogue which cloud apps employees actually use, exposing unsanctioned shadow IT. That visibility is the capability the stem asks for, distinct from session or access controls.

  • ✓

    Session control to monitor and control app access in real-time

    Why this is correct

    Session control proxies user sessions to cloud apps in real time, allowing conditional access policies to block downloads, encrypt files or restrict actions mid-session. This is the live monitoring and control capability the stem requires, unlike discovery's retrospective log analysis.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.