SC-100 Design security solutions for infrastructure Practice Question
Your organization has a Microsoft Defender for Cloud Apps policy that detects suspicious OAuth app permissions. You need to ensure that when a high-risk app is detected, the app is automatically disabled and the user is notified. What is the most efficient design?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the 'Disable app' governance action in the policy, and configure email notification
Microsoft Defender for Cloud Apps policies natively support governance actions such as 'Disable app,' which can be applied automatically when a policy match occurs, and the same policy can be configured to send email notifications to affected users, making this the most efficient single-policy design. Option B only notifies the user and does not disable the high-risk app, so it fails the requirement. Option C adds unnecessary complexity by routing the alert to Microsoft Sentinel and building a playbook, which is not the most efficient approach when the native governance action exists. Option D relies on an external Power Automate flow triggered by the alert, which is also less efficient than using the built-in 'Disable app' governance action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the 'Disable app' governance action in the policy, and configure email notification
Why this is correct
The 'Disable app' governance action is a native policy response in Microsoft Defender for Cloud Apps that instantly revokes access to the connected third-party app. Because it is a built-in governance action, you can also enable email notification in the same policy to alert the affected user, achieving both remediation and communication in one cohesive, low-latency step without any external orchestration.
- ✗
Configure the policy to notify the user via email
Why it's wrong here
Selecting only the email notification option leaves the app fully available to the user, so the policy is purely informational and lacks any enforcement. No governance action is taken to disable the app, meaning the non-compliant usage continues and the security objective is not achieved.
- ✗
Send the alert to Microsoft Sentinel and create an incident with a playbook
Why it's wrong here
Sending the alert to Microsoft Sentinel for a playbook to disable the app and notify the user is inefficient because Microsoft Defender for Cloud Apps policies can perform these direct governance actions natively and immediately. Sentinel playbooks are powerful for complex, cross-domain automation and orchestration, or when the source system lacks native capabilities, making it a tempting but less direct solution for this specific requirement. This approach would be suitable for broader incident response workflows involving multiple security tools or custom actions beyond Defender for Cloud Apps' built-in capabilities.
- ✗
Create a Power Automate flow that triggers on the alert to disable the app
Why it's wrong here
Creating a Power Automate flow to act on the alert introduces unnecessary complexity: the flow needs its own trigger, API permissions, and conditional logic, and it may not have a direct 'Disable app' connector action. Defender for Cloud Apps already provides a native 'Disable app' governance action, making the custom flow a redundant, slower, and more error-prone workaround compared to the built-in policy response.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.