Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Cloud Apps to discover shadow IT. You notice that a new cloud app is being used by multiple users but has a risk score of 8. What should you do first to manage the risk?

⚠ Common exam trap

A common mix-up: candidates assume a high risk score automatically requires immediate blocking or unsanctioning, but Microsoft's guidance emphasizes investigation first to avoid false positives and ensure business continuity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Investigate the app's risk factors and user activity

A risk score of 8 indicates the app is high-risk, but immediate blocking or unsanctioning could disrupt business operations if the app is legitimate or used for approved purposes. The first step is to investigate the app's risk factors (e.g., data residency, encryption standards, compliance certifications) and user activity (e.g., volume of data uploaded, types of files shared) to understand the actual threat. This aligns with Microsoft's recommended incident response process: assess before acting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Investigate the app's risk factors and user activity

    Why this is correct

    In Defender for Cloud Apps, investigation involves reviewing the app's cloud app catalog risk score, which includes factors such as data sharing, authentication methods, and compliance certifications, alongside actual user activity like sign-in events, file access, and IP addresses. This allows security analysts to differentiate unsanctioned but benign applications from those posing genuine threats such as credential theft or data exfiltration. By correlating risk factors with usage patterns, an analyst can make an informed governance decision—whether to sanction, alert, or block—without interrupting business continuity.

  • ✗

    Block the app at the proxy

    Why it's wrong here

    Blocking at the proxy, typically via a conditional access policy controlling traffic through Microsoft Entra application proxy or a third-party forward proxy, is disruptive because it prevents all users from reaching the app without first assessing whether the app is used for legitimate business purposes. This action could cause unplanned downtime for departments that rely on the app for collaboration or productivity, and it bypasses the step of reviewing risk indicators like session cookies, OAuth permissions, or file uploads. In Defender for Cloud Apps, blocking should be reserved for apps confirmed as high-risk or unsanctioned after investigation, not as a first response.

  • ✗

    Immediately unsanction the app in Defender for Cloud Apps

    Why it's wrong here

    Unsanctioning in Defender for Cloud Apps marks an app as disallowed, which causes the service to generate alerts and, when integrated with conditional access, can automatically redirect sessions to a block page or revoke OAuth token access. Doing so without prior investigation ignores that app-level risk scores may be inaccurate due to unverified community signals or shadow IT usage patterns, and it can lock users out of an app that is actually compliant with data protection policies. A proper workflow should first review discovery reports and user analytics to confirm that the app is truly against organizational policy, rather than making irreversible governance decisions reactively.

  • ✗

    Create a policy to alert on use of this app

    Why it's wrong here

    Creating a policy to alert on app usage—for example, an app discovery policy that triggers an alert when a new or risky app is accessed—provides visibility and helps security teams maintain a watchlist, but it only generates notifications; it does not translate those alerts into actionable remediation details. An alert alone lacks the contextual depth needed to understand whether the app's risk factors, like missing encryption at rest or a low CVSS score, are relevant to the organization's specific threat model. The correct sequence is to perform a manual investigation of the app's risk factors and user activity first, so that any alerting or blocking policy is configured with accurate thresholds and does not create noise.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.