Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your organization has a Microsoft Defender for Cloud Apps policy that detects suspicious OAuth app permissions. You need to ensure that when a high-risk app is detected, the app is automatically disabled and the user is notified. What is the most efficient design?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the 'Disable app' governance action in the policy, and configure email notification

Microsoft Defender for Cloud Apps policies natively support governance actions such as 'Disable app,' which can be applied automatically when a policy match occurs, and the same policy can be configured to send email notifications to affected users, making this the most efficient single-policy design. Option B only notifies the user and does not disable the high-risk app, so it fails the requirement. Option C adds unnecessary complexity by routing the alert to Microsoft Sentinel and building a playbook, which is not the most efficient approach when the native governance action exists. Option D relies on an external Power Automate flow triggered by the alert, which is also less efficient than using the built-in 'Disable app' governance action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use the 'Disable app' governance action in the policy, and configure email notification

    Why this is correct

    The 'Disable app' governance action is a native policy response in Microsoft Defender for Cloud Apps that instantly revokes access to the connected third-party app. Because it is a built-in governance action, you can also enable email notification in the same policy to alert the affected user, achieving both remediation and communication in one cohesive, low-latency step without any external orchestration.

  • ✗

    Configure the policy to notify the user via email

    Why it's wrong here

    Selecting only the email notification option leaves the app fully available to the user, so the policy is purely informational and lacks any enforcement. No governance action is taken to disable the app, meaning the non-compliant usage continues and the security objective is not achieved.

  • ✗

    Send the alert to Microsoft Sentinel and create an incident with a playbook

    Why it's wrong here

    Sending the alert to Microsoft Sentinel for a playbook to disable the app and notify the user is inefficient because Microsoft Defender for Cloud Apps policies can perform these direct governance actions natively and immediately. Sentinel playbooks are powerful for complex, cross-domain automation and orchestration, or when the source system lacks native capabilities, making it a tempting but less direct solution for this specific requirement. This approach would be suitable for broader incident response workflows involving multiple security tools or custom actions beyond Defender for Cloud Apps' built-in capabilities.

  • ✗

    Create a Power Automate flow that triggers on the alert to disable the app

    Why it's wrong here

    Creating a Power Automate flow to act on the alert introduces unnecessary complexity: the flow needs its own trigger, API permissions, and conditional logic, and it may not have a direct 'Disable app' connector action. Defender for Cloud Apps already provides a native 'Disable app' governance action, making the custom flow a redundant, slower, and more error-prone workaround compared to the built-in policy response.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.