SC-100 Practice Question: Design security solutions for applications and data
Your company uses Microsoft Defender for Cloud Apps to discover shadow IT. You need to ensure that data exfiltration from sanctioned cloud apps is blocked in real-time. Which control should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access App Control
Conditional Access App Control is the correct answer because it enables real-time session monitoring and control over sanctioned cloud apps, allowing you to block data exfiltration actions such as downloads, copy/paste, and uploads via reverse proxy integration with Microsoft Entra Conditional Access. It is specifically designed for inline enforcement on user sessions, which matches the requirement to block exfiltration in real time. IP address ranges are used for defining corporate network boundaries in Cloud Discovery, not for session-level blocking. Cloud discovery only identifies shadow IT usage from logs and does not enforce real-time controls. App connectors provide API-based visibility and governance for sanctioned apps but do not block user actions in real time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access App Control
Why this is correct
Conditional Access App Control is a reverse-proxy based capability that integrates with Microsoft Entra Conditional Access to enforce session policies on sanctioned cloud apps in real time. When a user accesses a configured app, the session is routed through Microsoft Defender for Cloud Apps, giving it the ability to inspect each request and response. This allows granular controls such as blocking downloads, preventing copy/paste, or forcing step-up authentication, which directly mitigates data exfiltration during the active session.
- ✗
IP address ranges
Why it's wrong here
IP address ranges identify source networks or geographic locations for conditional access policies, such as named locations to allow or block sign-ins. However, they are evaluated only at authentication time and do not provide any inline, per-request control over user actions within an already-established session. Consequently, they cannot block data exfiltration events like a file download or a copy/paste operation in real time.
- ✗
Cloud discovery
Why it's wrong here
Cloud discovery analyzes traffic logs to identify shadow IT—apps that users are accessing without official approval—and provides a risk score for each discovered app. This is fundamentally a visibility and assessment capability; it does not sit in the request path of a session and cannot enforce real-time actions on sanctioned apps. While it informs governance decisions, it lacks the inline session controls required to block data exfiltration during an active session.
- ✗
App connector
Why it's wrong here
App connectors use the provider's API to asynchronously ingest activity events from cloud apps, enabling monitoring, investigation, and automated alerts or action (e.g., suspend a user). This is a read-only, out-of-band integration: it does not intercept the user's traffic or mediate each request. Thus, it cannot react to data exfiltration at the moment it occurs in a session; it only reports or remediates after the fact.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.