SC-100 Practice Question: Design security solutions for applications and data
Your company uses Microsoft Defender for Cloud Apps to protect its SaaS environment. You need to configure settings to detect and block risky user activities. Which TWO actions should you take? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure anomaly detection policies.
Options C and E are correct. Configuring anomaly detection policies (Option C) helps identify unusual user behaviors that may indicate a security threat. Enabling session monitoring for critical applications (Option E) allows real-time monitoring and control of user activities, which can block risky actions as they occur. Option A is incorrect because blocking all third-party app access is overly restrictive and not a targeted measure for detecting risky user activities. Option B is incorrect because defining IP address ranges for trusted locations is for location-based policies, not for detecting risky behaviors. Option D is incorrect because app discovery policies are used to discover shadow IT, not to monitor or block risky user activities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block all third-party app access.
Why it's wrong here
While blocking all third-party app access would prevent unauthorized use, it is overly restrictive and harms business productivity by prohibiting legitimate SaaS applications that users rely on, such as CRM, file sharing, and collaboration tools. Defender for Cloud Apps does not encourage a blanket-block approach; instead, it supports granular controls such as app permission policies to revoke access for overprivileged apps and conditional access app control to restrict problematic actions within specific apps. This one-size-fits-all strategy also drives users to bypass security controls through shadow IT, because it ignores the need to balance security and enablement.
- ✗
Define IP address ranges for trusted locations.
Why it's wrong here
Defining IP address ranges for trusted locations is a configuration that tags known corporate egress addresses as 'Corporate' or 'Trusted' in Defender for Cloud Apps, refining location-based anomaly detection and access policies. This helps reduce false positives for events like impossible travel or sign-ins from unusual IPs, but it does not directly monitor, detect, or respond to risky user behaviors. It is a supporting input to risk scoring, not a protective control for user activities, so it cannot satisfy the requirement of protecting user behavior.
- ✓
Configure anomaly detection policies.
Why this is correct
Anomaly detection policies in Defender for Cloud Apps apply machine learning and user entity behavior analytics (UEBA) to establish baseline activity for each user and then flag deviations such as mass downloads, impossible travel, failed sign-ins, or unusual admin operations. These policies are purpose-built to detect risky behaviors, including compromised users and insider threats, and can trigger automated remediation through integration with Microsoft 365. Because the scenario asks for protecting user activities by detecting suspicious actions, this is the most directly relevant configuration.
- ✗
Configure app discovery policies.
Why it's wrong here
App discovery policies analyze network traffic logs to identify shadow IT and assess the risk of each cloud app that users are leveraging, such as discovering unsanctioned storage or collaboration tools. They focus on the inventory and risk rating of applications, not on the behavioral activities of users within those applications, so they cannot detect anomalies like data exfiltration or compromised accounts. While app discovery is valuable for governance and controlling app access, it does not provide the behavioral threat detection needed to protect user activities.
- ✓
Enable session monitoring for critical applications.
Why this is correct
Session monitoring through conditional access app control in Defender for Cloud Apps provides real-time visibility into and control over user actions in critical applications, enabling you to block downloads, restrict uploads, or require step-up authentication during a session. It is a valid supporting control for protecting high-risk apps, but it is policy-driven and reactionary—it activates only when a session matches preset conditions, unlike anomaly detection, which continuously learns and adapts to a user's behavioral baseline. In this scenario, session monitoring is complementary, not the primary method for detecting risky behaviors.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.