Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your organization is planning to deploy Microsoft Defender for Cloud Apps (formerly Cloud App Security). You need to discover shadow IT usage and control access to cloud apps. Which TWO capabilities should you enable? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access App Control

Cloud Discovery [E] is correct because it is the Defender for Cloud Apps feature that analyzes your traffic logs (from firewalls, proxies, or Defender for Endpoint) against the Cloud App Catalog to identify shadow IT usage, giving risk scores and usage analytics for discovered apps. Conditional Access App Control [A] is correct because it uses reverse-proxy deployment (via Microsoft Entra Conditional Access policies) to enforce real-time session controls—such as block download, block upload, and read-only access—on cloud apps, directly satisfying the requirement to control access to cloud apps. Intune device compliance policies [B] govern device health and compliance, not cloud app discovery or session-level app access control. DLP policies [C] protect sensitive data from exfiltration but do not perform shadow IT discovery or app access control. On-premises app discovery via Defender for Identity [D] only surfaces on-premises shadow IT (e.g., unsanctioned SaaS used from domain controllers), not the broad cloud app discovery and access control this scenario requires.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conditional Access App Control

    Why this is correct

    Conditional Access App Control (CAAC) is a session-level reverse proxy capability within Microsoft Defender for Cloud Apps that dynamically enforces access policies on cloud applications in real time. It can block downloads, restrict uploads, or require step-up authentication without modifying the app itself. This control operates after a user is authenticated and is ideal for protecting access to both sanctioned and unsanctioned cloud apps.

  • ✗

    Microsoft Intune device compliance policies

    Why it's wrong here

    Microsoft Intune device compliance policies govern device health, encryption, OS version, and configuration profiles, and they can feed into Conditional Access as conditions. However, they do not perform any discovery of cloud app usage or shadow IT, nor do they provide session-level control over SaaS application sessions. Device compliance is an access prerequisite, not a mechanism for continuous, per-app access enforcement.

  • ✗

    Data Loss Prevention (DLP) policies

    Why it's wrong here

    Data Loss Prevention (DLP) policies in Microsoft Purview protect sensitive data by inspecting content and applying actions like blocking or encryption. DLP does not identify which cloud applications exist in your environment or who is using them, and it cannot enforce session-level access restrictions at the application layer. The core functional gap here is discovery and access control, which DLP does not address.

  • ✗

    On-premises app discovery via Microsoft Defender for Identity

    Why it's wrong here

    Microsoft Defender for Identity (MDI) monitors on-premises Active Directory for malicious activities such as pass-the-hash and lateral movement, using domain controller logs and Kerberos data. It is not designed to discover cloud app usage or control access to SaaS applications; cloud app discovery requires traffic log ingestion through Defender for Cloud Apps, not MDI. The two products operate on entirely different data sources.

  • ✓

    Cloud Discovery

    Why this is correct

    Cloud Discovery is a feature of Microsoft Defender for Cloud Apps that analyzes traffic logs from proxy servers, firewalls, or endpoint agents to reveal the full inventory of cloud apps in use, including shadow IT. It assigns risk scores, identifies user activity, and surfaces unsanctioned applications that might present security risks. This discovery capability directly addresses the need to know what cloud apps are being used, and it feeds into policies for Conditional Access App Control.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.