Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

A company uses Microsoft Defender for Cloud Apps to discover and control Shadow IT. They want to block the use of a newly discovered unsanctioned app. What should they do?

⚠ Common exam trap

Many exam-takers assume creating a Conditional Access policy directly is the correct action, but the SC-100 exam tests the understanding that marking the app as unsanctioned in Defender for Cloud Apps is the prerequisite step that triggers the automatic Conditional Access policy enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Mark the app as unsanctioned in Defender for Cloud Apps

Marking an app as unsanctioned in Microsoft Defender for Cloud Apps is the direct mechanism to block access to a discovered Shadow IT app. When an app is marked unsanctioned, Defender for Cloud Apps automatically enforces a block by integrating with Conditional Access to prevent users from accessing the app, and it can also generate alerts and session controls. This action is specifically designed for the discovered app governance workflow within Defender for Cloud Apps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a Conditional Access policy to block the app

    Why it's wrong here

    Conditional Access policies primarily govern access to applications integrated with Microsoft Entra ID or sanctioned cloud apps. They cannot directly block a *newly discovered unsanctioned app* identified by Defender for Cloud Apps, which requires specific Shadow IT control mechanisms like API connectors or proxy integration. This option is tempting because CAPs are fundamental for enforcing access restrictions, including blocking, for *known* applications and resources protected by Microsoft Entra ID based on user and device conditions.

  • Use Microsoft Purview Data Loss Prevention to block the app

    Why it's wrong here

    Microsoft Purview Data Loss Prevention (DLP) policies inspect and protect sensitive content in emails, documents, and cloud data stores, applying actions such as blocking sharing or encrypting data when credit card numbers or PII are detected. They do not evaluate or restrict whether a user can reach a cloud app in the first place, so creating a DLP policy cannot stop access to a newly discovered app. Even though Defender for Cloud Apps can integrate with DLP for deeper content inspection, that integration is for data-level controls, not app-level access blocking.

  • Mark the app as unsanctioned in Defender for Cloud Apps

    Why this is correct

    Defender for Cloud Apps presents discovered apps in the Shadow IT dashboard, where an admin can mark an app as unsanctioned to actively block it. Unsanctioning is the native CASB control point that works with the Conditional Access App Control (reverse proxy) or app connectors to terminate sessions and prevent access to the app for all users. This is the exact feature designed to govern newly discovered unsanctioned cloud applications, and it works even for apps that are not federated with Microsoft Entra ID.

  • Block the app's domain in Microsoft Intune

    Why it's wrong here

    Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) solution that focuses on device compliance, configuration, and app lifecycle, such as deploying managed apps or preventing jailbroken devices from accessing corporate resources. Blocking a domain in Intune is not a supported mechanism for controlling access to cloud apps; domain blocking would be done by network security tools like DNS filtering or a web proxy. Intune cannot see the Shadow IT app inventory that Defender for Cloud Apps discovers, nor does it provide a cloud app blocking action.

About these practice questions

This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.