SC-200 Manage a security operations environment Practice Question
You are configuring Microsoft Defender for Cloud Apps with Cloud Discovery. You need to ensure that logs from your network proxies are processed correctly. Which THREE steps are required?
⚠ Common exam trap
It's easy for candidates to confuse the log collector with the Sentinel connector, thinking both are required for log ingestion, but the Sentinel connector is for SIEM integration, not for Cloud Discovery log processing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Upload the log files manually or configure automatic log upload using the log collector.
Microsoft Defender for Cloud Apps Cloud Discovery requires log data from network proxies to be ingested either by manually uploading log files or by configuring automatic log upload via the log collector. The log collector is a Docker-based container that parses and normalizes proxy logs before forwarding them to Defender for Cloud Apps, enabling shadow IT discovery without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Upload the log files manually or configure automatic log upload using the log collector.
Why this is correct
Defender for Cloud Apps Cloud Discovery has no visibility into your network traffic unless it receives the raw logs from your proxy, firewall, or other network appliances. You must either manually upload a flat log file through the Cloud Discovery 'Upload' dialog for an ad-hoc snapshot, or deploy the log collector to automate continuous ingestion, parsing, and forwarding. The log collector runs on Windows or Linux, receives logs via FTP/Syslog/HTTP, and is the standard for ongoing discovery. Without this step, no shadow IT analysis can occur, making it a required configuration action.
- ✗
Install the Microsoft Defender for Cloud Apps connector in Sentinel.
Why it's wrong here
The Microsoft Defender for Cloud Apps connector in Sentinel is an outbound data connector: it pulls alerts and activities from Defender for Cloud Apps into your Sentinel workspace for SIEM correlation, incident response, and hunting. It does not ingest or forward proxy logs to Cloud Discovery; that data flow is entirely unrelated to Sentinel. Installing this connector would not provide the network traffic logs that Cloud Discovery needs, and it would not enable or improve the log-processing pipeline. Therefore, it is not a valid configuration step for Cloud Discovery.
- ✗
Enable Azure Information Protection for labeling.
Why it's wrong here
Azure Information Protection (now integrated into Microsoft Purview Information Protection) is used for classifying and labeling sensitive documents and emails with sensitivity labels, encryption, and rights protection. It has no role in the Cloud Discovery log-analysis pipeline and is not a prerequisite for discovering shadow IT. Enabling AIP would neither facilitate log ingestion, parsing, nor traffic classification. This option is a distractor because both AIP and Cloud Discovery appear in the Defender portal, but they address entirely separate security functions with no operational dependency.
- ✓
Ensure proxy logs are in a supported format such as Common Log Format (CLF).
Why this is correct
Defender for Cloud Apps can only parse and analyze proxy logs that conform to a set of documented, supported schemas, and Common Log Format (CLF) is one such standard. Other supported formats include W3C, Squid, Blue Coat, and Cisco FWSM; if your proxy exports a proprietary or custom format, the log collector or manual upload will fail to parse it, resulting in gaps or complete loss of discovery data. Therefore, verifying and normalizing the log format is a necessary step before upload, and it is correctly identified as an action required to ensure Cloud Discovery functions.
- ✓
Configure the source IP address ranges of your organization in Defender for Cloud Apps settings.
Why this is correct
Configuring the public IP address ranges of your organization in Defender for Cloud Apps settings is essential because those ranges are used to classify internal traffic versus external traffic during log analysis. When the system sees a source IP within your defined ranges, it associates that traffic with your users rather than treating it as unknown external activity, which dramatically improves the accuracy of user identification in the discovery reports. This setting also affects privacy features such as user anonymization, allowing you to preserve external traffic visibility while correctly attributing internal usage. It is a required configuration step for a reliable Cloud Discovery deployment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.