Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company uses a third-party SaaS CRM application. The security team needs to monitor user sessions in real-time when sales representatives access the CRM from personal, unmanaged devices. The goal is to prevent the download of sensitive customer data to local drives. The solution should block download actions and show a warning to the user. Which Microsoft security solution should the team deploy to enforce these session controls?

⚠ Common exam trap

A common mix-up: candidates confuse the broad detection and response capabilities of Microsoft 365 Defender or Defender for Endpoint with the specific session-level enforcement provided by Defender for Cloud Apps, which is the only solution that can intercept and control user actions inside a third-party SaaS application in real time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps (MDCA) provides session-level controls via its Conditional Access App Control feature. This allows real-time monitoring and control of user sessions in third-party SaaS apps like CRM, enabling actions such as blocking downloads and displaying warnings based on device compliance (e.g., unmanaged devices). The solution integrates with Azure AD Conditional Access to enforce these policies at the session layer without modifying the underlying SaaS application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Cloud Apps

    Why this is correct

    Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing deep visibility and control over cloud applications. Through its Conditional Access App Control capabilities, it can proxy user sessions to third-party SaaS CRM applications in real-time. This allows for granular policy enforcement, such as blocking downloads of sensitive data to unmanaged devices, directly within the user's session, effectively preventing data loss.

  • Microsoft 365 Defender

    Why it's wrong here

    Microsoft 365 Defender is an Extended Detection and Response (XDR) solution that unifies protection, detection, investigation, and response across endpoints, identities, email, and cloud apps. It correlates signals from various Defender components to provide a holistic view of incidents. However, while it integrates telemetry from cloud applications, Microsoft 365 Defender itself is an overarching platform for incident management and does not directly provide the real-time session proxying and granular control capabilities required to block specific actions within a third-party SaaS application.

    When this WOULD be correct

    Microsoft 365 Defender would be correct if the question asked for a solution to correlate and respond to advanced attacks across email, endpoints, identities, and cloud apps, such as detecting a multi-stage phishing campaign that compromises a user's credentials and then moves laterally to exfiltrate data.

  • Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. Its primary function is to collect security data from various sources, detect threats using analytics and AI, and automate responses. However, Sentinel operates on logs and alerts post-event or for threat detection; it lacks the capability to proxy or directly intervene in a live user's web browser session to enforce real-time access or data exfiltration controls for SaaS applications.

    When this WOULD be correct

    A company needs to aggregate security logs from multiple sources (e.g., firewalls, servers, cloud apps) and create custom alerts for anomalous user behavior. Microsoft Sentinel would be the correct answer for centralized threat detection and incident response.

  • Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint is an enterprise endpoint security platform designed to protect devices from cyber threats, providing capabilities like endpoint detection and response (EDR), vulnerability management, and next-generation antivirus. While it secures the device itself, it does not possess the functionality to monitor or control user actions within a web browser session for a third-party SaaS application, nor can it enforce policies like blocking downloads from a cloud app directly.

    When this WOULD be correct

    An exam question might ask: 'Which Microsoft solution provides endpoint detection and response, antivirus, and vulnerability management for devices?' In that context, Microsoft Defender for Endpoint would be the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft Defender for Cloud AppsCorrect answer

Why this is correct

Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing deep visibility and control over cloud applications. Through its Conditional Access App Control capabilities, it can proxy user sessions to third-party SaaS CRM applications in real-time. This allows for granular policy enforcement, such as blocking downloads of sensitive data to unmanaged devices, directly within the user's session, effectively preventing data loss.

Microsoft 365 DefenderWrong answer — click to see why

Why this is wrong here

Microsoft 365 Defender is a unified pre- and post-breach enterprise defense suite that correlates signals across identities, endpoints, and data, but it does not provide real-time session monitoring and control for third-party SaaS apps like the CRM in this scenario.

★ When this WOULD be the correct answer

Microsoft 365 Defender would be correct if the question asked for a solution to correlate and respond to advanced attacks across email, endpoints, identities, and cloud apps, such as detecting a multi-stage phishing campaign that compromises a user's credentials and then moves laterally to exfiltrate data.

Why candidates choose this

Candidates may confuse Microsoft 365 Defender's broad security coverage with the specific session control capabilities of Defender for Cloud Apps, or they may think that 'Defender' products all include similar app control features.

Microsoft SentinelWrong answer — click to see why

Why this is wrong here

Microsoft Sentinel is a SIEM/SOAR solution for security analytics and threat intelligence, not for real-time session control or conditional access policies. It does not natively block downloads or enforce session policies in third-party SaaS apps.

★ When this WOULD be the correct answer

A company needs to aggregate security logs from multiple sources (e.g., firewalls, servers, cloud apps) and create custom alerts for anomalous user behavior. Microsoft Sentinel would be the correct answer for centralized threat detection and incident response.

Why candidates choose this

Candidates may confuse Sentinel's monitoring capabilities with the session control features of Defender for Cloud Apps, assuming any Microsoft security tool can enforce real-time policies on SaaS apps.

Microsoft Defender for EndpointWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR) for devices, not on session-level control for SaaS applications. It cannot block download actions or show warnings within a third-party CRM session.

★ When this WOULD be the correct answer

An exam question might ask: 'Which Microsoft solution provides endpoint detection and response, antivirus, and vulnerability management for devices?' In that context, Microsoft Defender for Endpoint would be the correct answer.

Why candidates choose this

Candidates may confuse Defender for Endpoint with Defender for Cloud Apps because both have 'Defender' in the name and relate to security, leading them to assume endpoint protection can control SaaS app sessions.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Go deeper

Related to this question

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.