SC-100 Design security solutions for infrastructure Practice Question
Your organization is planning to deploy Microsoft Defender for Cloud Apps (formerly Cloud App Security). You need to discover shadow IT usage and control access to cloud apps. Which TWO capabilities should you enable? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access App Control
Cloud Discovery [E] is correct because it is the Defender for Cloud Apps feature that analyzes your traffic logs (from firewalls, proxies, or Defender for Endpoint) against the Cloud App Catalog to identify shadow IT usage, giving risk scores and usage analytics for discovered apps. Conditional Access App Control [A] is correct because it uses reverse-proxy deployment (via Microsoft Entra Conditional Access policies) to enforce real-time session controls—such as block download, block upload, and read-only access—on cloud apps, directly satisfying the requirement to control access to cloud apps. Intune device compliance policies [B] govern device health and compliance, not cloud app discovery or session-level app access control. DLP policies [C] protect sensitive data from exfiltration but do not perform shadow IT discovery or app access control. On-premises app discovery via Defender for Identity [D] only surfaces on-premises shadow IT (e.g., unsanctioned SaaS used from domain controllers), not the broad cloud app discovery and access control this scenario requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access App Control
Why this is correct
Conditional Access App Control (CAAC) is a session-level reverse proxy capability within Microsoft Defender for Cloud Apps that dynamically enforces access policies on cloud applications in real time. It can block downloads, restrict uploads, or require step-up authentication without modifying the app itself. This control operates after a user is authenticated and is ideal for protecting access to both sanctioned and unsanctioned cloud apps.
- ✗
Microsoft Intune device compliance policies
Why it's wrong here
Microsoft Intune device compliance policies govern device health, encryption, OS version, and configuration profiles, and they can feed into Conditional Access as conditions. However, they do not perform any discovery of cloud app usage or shadow IT, nor do they provide session-level control over SaaS application sessions. Device compliance is an access prerequisite, not a mechanism for continuous, per-app access enforcement.
- ✗
Data Loss Prevention (DLP) policies
Why it's wrong here
Data Loss Prevention (DLP) policies in Microsoft Purview protect sensitive data by inspecting content and applying actions like blocking or encryption. DLP does not identify which cloud applications exist in your environment or who is using them, and it cannot enforce session-level access restrictions at the application layer. The core functional gap here is discovery and access control, which DLP does not address.
- ✗
On-premises app discovery via Microsoft Defender for Identity
Why it's wrong here
Microsoft Defender for Identity (MDI) monitors on-premises Active Directory for malicious activities such as pass-the-hash and lateral movement, using domain controller logs and Kerberos data. It is not designed to discover cloud app usage or control access to SaaS applications; cloud app discovery requires traffic log ingestion through Defender for Cloud Apps, not MDI. The two products operate on entirely different data sources.
- ✓
Cloud Discovery
Why this is correct
Cloud Discovery is a feature of Microsoft Defender for Cloud Apps that analyzes traffic logs from proxy servers, firewalls, or endpoint agents to reveal the full inventory of cloud apps in use, including shadow IT. It assigns risk scores, identifies user activity, and surfaces unsanctioned applications that might present security risks. This discovery capability directly addresses the need to know what cloud apps are being used, and it feeds into policies for Conditional Access App Control.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.