SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company uses a third-party SaaS CRM application. The security team needs to monitor user sessions in real-time when sales representatives access the CRM from personal, unmanaged devices. The goal is to prevent the download of sensitive customer data to local drives. The solution should block download actions and show a warning to the user. Which Microsoft security solution should the team deploy to enforce these session controls?
⚠ Common exam trap
A common mix-up: candidates confuse the broad detection and response capabilities of Microsoft 365 Defender or Defender for Endpoint with the specific session-level enforcement provided by Defender for Cloud Apps, which is the only solution that can intercept and control user actions inside a third-party SaaS application in real time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps (MDCA) provides session-level controls via its Conditional Access App Control feature. This allows real-time monitoring and control of user sessions in third-party SaaS apps like CRM, enabling actions such as blocking downloads and displaying warnings based on device compliance (e.g., unmanaged devices). The solution integrates with Azure AD Conditional Access to enforce these policies at the session layer without modifying the underlying SaaS application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Cloud Apps
Why this is correct
Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing deep visibility and control over cloud applications. Through its Conditional Access App Control capabilities, it can proxy user sessions to third-party SaaS CRM applications in real-time. This allows for granular policy enforcement, such as blocking downloads of sensitive data to unmanaged devices, directly within the user's session, effectively preventing data loss.
- ✗
Microsoft 365 Defender
Why it's wrong here
Microsoft 365 Defender is an Extended Detection and Response (XDR) solution that unifies protection, detection, investigation, and response across endpoints, identities, email, and cloud apps. It correlates signals from various Defender components to provide a holistic view of incidents. However, while it integrates telemetry from cloud applications, Microsoft 365 Defender itself is an overarching platform for incident management and does not directly provide the real-time session proxying and granular control capabilities required to block specific actions within a third-party SaaS application.
When this WOULD be correct
Microsoft 365 Defender would be correct if the question asked for a solution to correlate and respond to advanced attacks across email, endpoints, identities, and cloud apps, such as detecting a multi-stage phishing campaign that compromises a user's credentials and then moves laterally to exfiltrate data.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. Its primary function is to collect security data from various sources, detect threats using analytics and AI, and automate responses. However, Sentinel operates on logs and alerts post-event or for threat detection; it lacks the capability to proxy or directly intervene in a live user's web browser session to enforce real-time access or data exfiltration controls for SaaS applications.
When this WOULD be correct
A company needs to aggregate security logs from multiple sources (e.g., firewalls, servers, cloud apps) and create custom alerts for anomalous user behavior. Microsoft Sentinel would be the correct answer for centralized threat detection and incident response.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Microsoft Defender for Endpoint is an enterprise endpoint security platform designed to protect devices from cyber threats, providing capabilities like endpoint detection and response (EDR), vulnerability management, and next-generation antivirus. While it secures the device itself, it does not possess the functionality to monitor or control user actions within a web browser session for a third-party SaaS application, nor can it enforce policies like blocking downloads from a cloud app directly.
When this WOULD be correct
An exam question might ask: 'Which Microsoft solution provides endpoint detection and response, antivirus, and vulnerability management for devices?' In that context, Microsoft Defender for Endpoint would be the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Defender for Cloud AppsCorrect answer▾
Why this is correct
Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing deep visibility and control over cloud applications. Through its Conditional Access App Control capabilities, it can proxy user sessions to third-party SaaS CRM applications in real-time. This allows for granular policy enforcement, such as blocking downloads of sensitive data to unmanaged devices, directly within the user's session, effectively preventing data loss.
✗Microsoft 365 DefenderWrong answer — click to see why▾
Why this is wrong here
Microsoft 365 Defender is a unified pre- and post-breach enterprise defense suite that correlates signals across identities, endpoints, and data, but it does not provide real-time session monitoring and control for third-party SaaS apps like the CRM in this scenario.
★ When this WOULD be the correct answer
Microsoft 365 Defender would be correct if the question asked for a solution to correlate and respond to advanced attacks across email, endpoints, identities, and cloud apps, such as detecting a multi-stage phishing campaign that compromises a user's credentials and then moves laterally to exfiltrate data.
Why candidates choose this
Candidates may confuse Microsoft 365 Defender's broad security coverage with the specific session control capabilities of Defender for Cloud Apps, or they may think that 'Defender' products all include similar app control features.
✗Microsoft SentinelWrong answer — click to see why▾
Why this is wrong here
Microsoft Sentinel is a SIEM/SOAR solution for security analytics and threat intelligence, not for real-time session control or conditional access policies. It does not natively block downloads or enforce session policies in third-party SaaS apps.
★ When this WOULD be the correct answer
A company needs to aggregate security logs from multiple sources (e.g., firewalls, servers, cloud apps) and create custom alerts for anomalous user behavior. Microsoft Sentinel would be the correct answer for centralized threat detection and incident response.
Why candidates choose this
Candidates may confuse Sentinel's monitoring capabilities with the session control features of Defender for Cloud Apps, assuming any Microsoft security tool can enforce real-time policies on SaaS apps.
✗Microsoft Defender for EndpointWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR) for devices, not on session-level control for SaaS applications. It cannot block download actions or show warnings within a third-party CRM session.
★ When this WOULD be the correct answer
An exam question might ask: 'Which Microsoft solution provides endpoint detection and response, antivirus, and vulnerability management for devices?' In that context, Microsoft Defender for Endpoint would be the correct answer.
Why candidates choose this
Candidates may confuse Defender for Endpoint with Defender for Cloud Apps because both have 'Defender' in the name and relate to security, leading them to assume endpoint protection can control SaaS app sessions.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Network Access Control
Network Access Control is a security solution that enforces policies to control which devices and users can connect to a network, ensuring only authorized and compliant endpoints gain access.
Key term
Defender for Cloud Apps
Defender for Cloud Apps is a Microsoft cloud access security broker (CASB) that helps you discover, protect, and govern your cloud applications and data across multiple cloud environments.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.