Enable Microsoft Defender for Cloud Apps Monitoring
Your organization is deploying Microsoft Defender for Cloud Apps. Which THREE capabilities are included in Defender for Cloud Apps? (Select three.)
⚠ Common exam trap
A common mix-up: candidates confuse integrated features with native capabilities: candidates often select DLP policies or Conditional Access because Defender for Cloud Apps integrates with them, but the question asks for capabilities included in Defender for Cloud Apps itself, not those it leverages from other services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session controls
Session controls (A) are a core Defender for Cloud Apps capability, delivered through Conditional Access App Control, which lets you monitor and restrict user sessions in real time (for example, blocking downloads or requiring reauthentication) for SaaS apps. App governance (B) is included in Defender for Cloud Apps and provides visibility, policy enforcement, and remediation for OAuth-enabled apps and their permissions across Microsoft 365 and other connected apps. Cloud Discovery (C) is also a foundational Defender for Cloud Apps feature that analyzes traffic logs to identify shadow IT and assess the risk of cloud apps in use. DLP policies (D) are not a native Defender for Cloud Apps capability; data protection is handled by Microsoft Purview DLP and can be surfaced in Defender for Cloud Apps, but the policy engine itself belongs to Purview. Conditional Access (E) is a Microsoft Entra ID feature, not a Defender for Cloud Apps capability, although Defender for Cloud Apps integrates with it for app control and risk-based policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Session controls
Why this is correct
Session controls in Microsoft Defender for Cloud Apps enforce real-time monitoring and control of user sessions via a reverse proxy. They allow organizations to apply granular access policies on cloud apps, such as preventing downloads, blocking access to sensitive files, or requiring step-up authentication. Session controls operate at the data plane level, evaluating user activity as it happens, and are often triggered by Conditional Access policies from Microsoft Entra ID.
- ✓
App governance
Why this is correct
App governance is a Microsoft Defender for Cloud Apps feature that specifically monitors and manages OAuth-enabled third-party applications. It provides visibility into app permissions, who granted them, and the risk associated with each app. Administrators can use automated policies to disable or revoke permissions for risky apps, ensuring that over-privileged or malicious apps do not access organizational data.
- ✓
Cloud Discovery
Why this is correct
Cloud Discovery is a Microsoft Defender for Cloud Apps capability that identifies shadow IT by analyzing network traffic logs from sources like Microsoft Defender for Endpoint, Zscaler, or VPN gateways. It discovers which cloud apps are being used across the organization, scores each app based on risk factors such as data leakage and regulatory compliance, and allows administrators to sanction or unsanction those apps to enforce governance.
- ✗
Data Loss Prevention (DLP) policies
Why it's wrong here
Data Loss Prevention (DLP) policies are not a native Defender for Cloud Apps feature; they belong to Microsoft Purview and Microsoft 365 compliance suite. While Defender for Cloud Apps can integrate with Purview to apply DLP policies to cloud apps, the policies themselves are defined and managed in Purview. Thus, DLP policies cannot be considered a core capability of Defender for Cloud Apps.
- ✗
Conditional Access
Why it's wrong here
Conditional Access is an identity-centric policy evaluation engine that is part of Microsoft Entra ID (formerly Azure Active Directory), not a feature of Microsoft Defender for Cloud Apps. It uses signals like user identity, device compliance, and location to grant or block authentication and has historically been a critical access control mechanism for IT. Defender for Cloud Apps can integrate with Conditional Access to enable session controls, but Conditional Access itself is external to the CASB product.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.