SC-100 Practice Question: Design security solutions for applications and data
Your organization is implementing Microsoft Defender for Cloud Apps to protect against malicious OAuth app permissions. Users have been granting permissions to third-party apps that request excessive scopes. What should you configure to automatically revoke such permissions?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
OAuth app policies in Defender for Cloud Apps
The correct option is A, OAuth app policies in Defender for Cloud Apps. These policies are purpose-built to detect risky or over-privileged OAuth apps and can automatically revoke user-granted permissions or disable the app when it matches conditions such as excessive scopes or low community use. Intune app protection policies (B) govern mobile app data handling (MAM) and do not revoke OAuth consent grants. Conditional Access policies (C) control sign-in conditions and session access, not OAuth permission revocation. Microsoft Entra ID app permissions management (D) allows reviewing and revoking consent grants manually but does not provide the automated, risk-based revocation that Defender for Cloud Apps OAuth app policies deliver.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
OAuth app policies in Defender for Cloud Apps
Why this is correct
OAuth app policies in Defender for Cloud Apps are the correct choice because they specifically enable automated governance for third-party applications that have been granted consent in Microsoft Entra ID. These policies can continuously monitor the app's activity, user involvement, and permissions, and automatically revoke access or apply a quarantine action when the app is deemed risky or exceeds a preset threshold. Unlike manual remediation, these policies execute the revocation directly on the OAuth application, removing its granted permissions without requiring a user to revoke consent manually.
- ✗
Microsoft Intune app protection policies
Why it's wrong here
Microsoft Intune app protection policies (APP) focus on protecting corporate data on managed devices through data-loss prevention controls, such as copy/paste restrictions, encryption, and conditional launch actions. They operate at the client app layer, not at the Microsoft Entra ID OAuth consent layer, and therefore cannot revoke permissions that an app has been granted. Even if an app is managed by Intune, its OAuth permissions in the tenant remain intact unless a separate mechanism like Defender for Cloud Apps policies intervenes.
- ✗
Conditional Access policies
Why it's wrong here
Conditional Access policies are enforced during authentication and can block a user's sign-in based on conditions like user risk, device compliance, or location, thereby preventing access to the app's resources. However, they do not revoke the OAuth permissions that were previously granted to the app; the app's delegated permissions in Microsoft Entra ID remain valid. Even if a Conditional Access policy blocks all users, the app itself still holds the granted permissions and could potentially access resources via non-interactive flows without a policy check.
- ✗
Microsoft Entra ID app permissions management
Why it's wrong here
Microsoft Entra ID (Entra) app permissions management refers to features such as Microsoft Entra Permissions Management (CIEM) that provide visibility and analysis of the permissions granted to apps across the environment. While this tooling can identify overprivileged apps and highlight risky permission grants, it does not include built-in automatic revocation workflows. You would still need to manually revoke the app's permissions or integrate with Defender for Cloud Apps policies to achieve automated remediation, which is why this is an incomplete answer.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.