Courseiva

SC-200 Manage a security operations environment Practice Question

You are managing Microsoft Defender for Cloud Apps. Which TWO actions can be performed using the Microsoft Defender XDR integration?

⚠ Common exam trap

It's easy for candidates to confuse the scope of Defender for Cloud Apps with broader Microsoft 365 security features, assuming it can perform email quarantine (A) or endpoint management (D, E) when those actions belong to separate products like Defender for Office 365 and Intune.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Investigate user activities across cloud apps.

Microsoft Defender XDR integration with Defender for Cloud Apps enables cross-domain investigation of user activities across cloud apps, leveraging signals from Microsoft 365 Defender to correlate events like sign-ins, file downloads, and admin actions. This allows security analysts to trace a user's behavior across SaaS applications (e.g., SharePoint, OneDrive, Teams) without switching consoles, using the unified incidents and alerts in the Microsoft 365 Defender portal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Quarantine malicious emails.

    Why it's wrong here

    Quarantining malicious emails is a native capability of Microsoft Defender for Office 365 (MDO), not Microsoft Defender for Cloud Apps. MDO inspects email transport, attachments, and URLs using threat intelligence and applies quarantine actions that suspend delivery to user mailboxes. Defender for Cloud Apps operates at the cloud application layer, connecting via APIs to apps like Office 365, and does not process email transport queues or mailbox-level quarantine policies.

  • ✓

    Investigate user activities across cloud apps.

    Why this is correct

    Defender for Cloud Apps collects activity log from connected cloud apps, such as Office 365, AWS, and Google Workspace, and presents them in a unified investigation experience. Analysts can search a user's activity timeline, cross-correlate with alerts from Microsoft Defender XDR, and trace the scope of a compromise across multiple SaaS services. This investigation capability directly addresses security incidents that span cloud applications, making it a core function of a CASB.

  • ✓

    Govern discovered apps with access policies.

    Why this is correct

    Cloud Discovery in Defender for Cloud Apps analyzes traffic logs to identify shadow IT, and access policies allow you to govern those discovered apps. Using conditional access app control, you can enforce session policies that block or restrict a discovered app based on its risk score, the user's group, or the device's compliance state. This extends governance to unsanctioned applications without requiring administrative access inside the app itself, providing real-time controls over app usage.

  • ✗

    Manage device compliance policies in Microsoft Intune.

    Why it's wrong here

    Device compliance policies are managed exclusively within Microsoft Intune, which is the lifecycle and endpoint management platform. Defender for Cloud Apps neither creates nor edits compliance policy rules; it can only consume device health signals produced by Intune when enforcing conditional access or session policies. The CASB's role is to evaluate cloud app context and user behavior, not to define the compliance baselines for managed devices.

  • ✗

    Onboard devices to Microsoft Defender for Endpoint.

    Why it's wrong here

    Onboarding devices to Microsoft Defender for Endpoint is achieved through Microsoft Endpoint Manager (Intune), local group policy, or the Defender for Cloud onboarding wizard, not via Defender for Cloud Apps. Defender for Cloud Apps is a cloud access security broker that relies on API connections and network traffic logs; it has no mechanism to install endpoint agents, register machines, or manage the Defender for Endpoint sensor state.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.