SC-100 Practice Question: Design security solutions for applications and data
Your organization wants to enable Microsoft Defender for Cloud Apps to monitor and control the use of Box and Dropbox. Which TWO steps must you perform?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Connect the app using an app connector
Option A is correct because Defender for Cloud Apps monitors and governs sanctioned SaaS apps such as Box and Dropbox by connecting them through an app connector (API connector), which uses the app's APIs and OAuth to pull activity logs, files, and user data for governance and control. Option D is correct because Conditional Access App Control (session control) uses Microsoft Entra Conditional Access policies and a reverse proxy to enforce real-time session controls like block download, block upload, and read-only access for Box and Dropbox. Option B is incorrect because adding apps to the unsanctioned list only tags them in Cloud Discovery as unsanctioned; it does not enable monitoring or control of the apps. Option C is incorrect because a forward proxy is not required; Cloud Discovery can use log upload or Defender for Cloud Apps log collectors, and session control uses a reverse proxy, not a forward proxy. Option E is incorrect because running a Cloud Discovery report only provides visibility into discovered apps and does not by itself enable monitoring and control of Box and Dropbox.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Connect the app using an app connector
Why this is correct
App connectors in Microsoft Defender for Cloud Apps leverage the cloud provider's native APIs (e.g., Box and Dropbox REST APIs) to pull metadata, activities, and file content for continuous, near-real-time monitoring. This allows you to enforce data loss prevention policies, detect user anomalies, and apply governance actions without relying on traffic interception. This is the correct method because it integrates directly with the apps you want to monitor and control, giving you full visibility and control over sanctioned usage.
- ✗
Add Box and Dropbox to the unsanctioned list
Why it's wrong here
Adding Box and Dropbox to the unsanctioned list would block or restrict access to these apps, which is the opposite of what the organization wants. The unsanctioned list is intended for shadow IT apps discovered during cloud discovery that are deemed dangerous or non-compliant. Since your goal is to enable monitoring and control rather than prohibit usage, unsanctioning these apps would deny users access entirely and prevent Defender for Cloud Apps from enforcing policies or providing the desired oversight.
- ✗
Deploy a forward proxy
Why it's wrong here
A forward proxy sits between clients and the internet, forwarding outbound requests, but Defender for Cloud Apps does not use forward proxies for its core features. Instead, it uses a reverse proxy—implemented through Conditional Access App Control—to intercept and inspect user sessions to sanctioned cloud apps. Deploying a forward proxy would require complex traffic redirection and would not provide API-level visibility into Box or Dropbox; it also would not integrate with Microsoft Entra ID conditional access or deliver the granular file and activity monitoring that app connectors offer.
- ✓
Configure Conditional Access App Control
Why this is correct
Configuring Conditional Access App Control is a correct and complementary action because it enables real-time, session-level monitoring and control by routing user sessions through Defender for Cloud Apps' reverse proxy. It works with Microsoft Entra Conditional Access policies to apply context-aware rules, such as blocking downloads from unmanaged devices or protecting sensitive files in Box and Dropbox. While this is a valid method to achieve monitoring and control, it is separate from the API-based app connector, which provides continuous out-of-band visibility even when users are not actively in a session.
- ✗
Run a cloud discovery report
Why it's wrong here
Running a cloud discovery report is not the right approach because discovery is designed to identify unknown or unsanctioned cloud apps by analyzing network traffic logs. Since Box and Dropbox are already known and presumably sanctioned for business use, discovery would only confirm their usage and maybe show usage patterns, but it would not grant Defender for Cloud Apps the ability to monitor and control them. Discovery is a precursor to deciding whether to sanction or unsanction an app; here the decision to enable monitoring already exists, so app connectors are the appropriate next step.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.