Courseiva

Microsoft Defender for Cloud Apps Capabilities

Which THREE capabilities are provided by Microsoft Defender for Cloud Apps (MDA) when integrated with Microsoft Defender XDR?

Quick Answer

The answer is shadow IT discovery, conditional access session controls, and cloud app catalog classification. These three capabilities are provided by Microsoft Defender for Cloud Apps when integrated with Microsoft Defender XDR because the integration enables real-time traffic log analysis from network devices and cloud app catalogs to identify unsanctioned applications, while conditional access session controls enforce granular policies on sanctioned apps at the session level. On the Microsoft Cybersecurity Architect exam, this question tests your understanding of how MDA extends XDR’s visibility beyond endpoints into SaaS and PaaS environments, often appearing as a multi-select scenario where you must distinguish MDA-specific features from general XDR capabilities. A common trap is confusing app governance or DLP policies, which are shared services, with MDA’s unique shadow IT and session control functions. Memory tip: think “Discover, Control, Catalog” — the three pillars of MDA integration with XDR.

⚠ Common exam trap

Many candidates confuse the capabilities of Microsoft Defender for Cloud Apps with those of other Microsoft Defender XDR components, such as Defender for Office 365 (email security) or Defender for Endpoint (EDR), leading them to select options that are valid security features but not provided by MDA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Discovery of shadow IT cloud apps.

Microsoft Defender for Cloud Apps (MDA) integrates with Microsoft Defender XDR to provide shadow IT discovery by analyzing traffic logs from network devices and cloud app catalogs, identifying unsanctioned cloud applications used in the organization. This capability is core to MDA's Cloud Discovery feature, which uses log parsing and machine learning to detect and classify shadow IT.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Email protection against phishing and malware.

    Why it's wrong here

    Email protection is from Defender for Office 365.

  • ✓

    Discovery of shadow IT cloud apps.

    Why this is correct

    MDA discovers apps used in the organization.

  • ✓

    App permissions and OAuth app governance.

    Why this is correct

    MDA manages third-party app permissions.

  • ✗

    Endpoint detection and response (EDR) for devices.

    Why it's wrong here

    EDR is from Defender for Endpoint.

  • ✓

    Conditional access session controls for cloud apps.

    Why this is correct

    Session policies control access in real-time.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You are analyzing a custom detection rule in Microsoft 365 Defender. Based on the exhibit, what is a potential operational issue with this rule?

hard
  • ✓ A.The threshold is too low, leading to alert fatigue.
  • B.The query syntax is invalid.
  • C.The severity should be Medium instead of High.
  • D.The rule does not cover PowerShell 7 (pwsh.exe).

Why A: Option A is correct because a custom detection rule whose threshold is set too low will trigger on very few or even a single event, generating excessive alerts that overwhelm analysts with false positives and cause alert fatigue. In Microsoft 365 Defender custom detections, the threshold (aggregation) value controls how many events must occur within the query's timeframe before an alert fires, so setting it too low directly increases alert volume. Option B is incorrect because the scenario asks about an operational issue, not a syntax error, and the exhibit implies the query runs. Option C is incorrect because severity is a triage preference, not an operational defect, and changing High to Medium would not fix alert volume. Option D is incorrect because PowerShell 7 coverage depends on the query's data source and process filters, not on the threshold, and the scenario does not indicate pwsh.exe is relevant.

Variation 2. Refer to the exhibit. You are analyzing a KQL query in Microsoft Sentinel. What is the primary purpose of this query?

hard
  • A.To summarize Mimikatz alerts by account.
  • B.To create an automation rule based on the query.
  • ✓ C.To enrich Mimikatz alerts with user account names.
  • D.To detect lateral movement after a Mimikatz alert.

Why C: The correct option is C: the query's purpose is to enrich Mimikatz alerts with user account names. In Microsoft Sentinel, KQL queries that join SecurityAlert data with identity tables (such as IdentityInfo or SecurityAlert's ExtendedProperties/Entities) are used to add contextual user account details to existing alerts, which is exactly what enrichment means. Option A is wrong because summarizing by account would use summarize/aggregation operators to produce counts, not add account names to alerts. Option B is wrong because automation rules are configured in the Sentinel UI (or via ARM/API), not created by a KQL query itself. Option D is wrong because detecting lateral movement would require correlating multiple log sources and suspicious sign-in or process events, not merely attaching account names to Mimikatz alerts.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.