Courseiva
mediumDrag & Drop

SC-200 Practice Question: Arrange the steps to deploy Microsoft Defender…

Arrange the steps to deploy Microsoft Defender for Cloud Apps (formerly MCAS) and connect it to a cloud app.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Step 1: Add an app connector for the cloud app. Step 2: Authenticate the connector. Step 3: Enable monitoring and policies.

Deploying Cloud App Security involves adding an app connector and authenticating to enable monitoring and control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Step 1: Add an app connector for the cloud app. Step 2: Authenticate the connector. Step 3: Enable monitoring and policies.

    Why this is correct

    Adding the app connector first creates the integration object in Defender for Cloud Apps that points to the cloud app's API endpoint. Authenticating the connector then completes the OAuth or credential flow, granting Defender for Cloud Apps the permissions needed to read logs and activities. Only after authentication can monitoring and policies be enabled, because they consume the authorized data stream supplied by the connector.

  • ✗

    Step 1: Enable monitoring and policies. Step 2: Add an app connector. Step 3: Authenticate the connector.

    Why it's wrong here

    Attempting to enable monitoring and policies at step one is logically impossible because there is no data source yet — the connector that would pull activity logs and user events has not been created. Monitoring features such as anomaly detection and policy enforcement rely entirely on data flowing from an authenticated connector; without it, they have nothing to inspect. The connector must be added and authenticated before monitoring can be toggled on, so this order fails.

  • ✗

    Step 1: Authenticate the connector. Step 2: Add an app connector. Step 3: Enable monitoring and policies.

    Why it's wrong here

    You cannot authenticate a connector before the connector exists, because authentication is performed against the specific connector instance added for a given cloud app. In the Defender for Cloud Apps portal, the first action is to select 'Connect an app' from the App connectors page, which creates that instance; only then does the portal present the authentication/consent screen. Authenticating first would leave the returned OAuth tokens with nothing to attach to, making the step meaningless.

  • ✗

    Step 1: Add an app connector. Step 2: Enable monitoring and policies. Step 3: Authenticate the connector.

    Why it's wrong here

    This sequence includes the fatal flaw of enabling monitoring and policies before the connector is authenticated, so the connector lacks permissions to query the cloud app's APIs and deliver activity data. Adding the connector first is correct, but skipping authentication means the monitoring engine is switched on while the data pipeline remains empty, and policies would never evaluate any real events. You must authenticate immediately after adding the connector and before enabling monitoring so that authorization is in place to collect data.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.