Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company uses Microsoft 365 and many third-party SaaS apps like Salesforce and Box. The security team wants to detect when a user downloads a large number of files from a cloud storage app after hours, which may indicate data exfiltration. Which Microsoft security solution should be used to detect such anomalous behavior in cloud apps?

⚠ Common exam trap

Watch out — candidates often confuse Microsoft Defender for Cloud Apps with Microsoft Defender for Cloud, mistakenly thinking the latter covers SaaS app security, when in fact Defender for Cloud is focused on infrastructure workload protection (CSPM/CWPP) and not user behavior in cloud apps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps (MDCA) is the correct solution because it provides Cloud Access Security Broker (CASB) functionality, including anomaly detection policies that can identify unusual user behavior such as downloading a large number of files from a cloud storage app after hours. MDCA uses machine learning to establish a baseline of normal user activity and then triggers alerts when deviations like high-volume downloads occur, which is a classic indicator of data exfiltration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Office 365

    Why it's wrong here

    Microsoft Defender for Office 365 is specifically engineered to safeguard an organization's Microsoft 365 environment by protecting against advanced threats like phishing, malware, and business email compromise across email, SharePoint Online, OneDrive for Business, and Microsoft Teams. While essential for securing Microsoft's own collaboration and productivity services, its scope does not extend to monitoring or detecting security incidents within third-party Software as a Service (SaaS) applications.

  • Microsoft Defender for Identity

    Why it's wrong here

    Microsoft Defender for Identity is a cloud-based security solution primarily focused on protecting hybrid identity environments by leveraging signals from on-premises Active Directory domain controllers and AD FS servers. It specializes in identifying, detecting, and investigating advanced threats, compromised identities, and malicious insider actions within the Active Directory infrastructure. This solution is not designed to provide visibility or security monitoring for user activities occurring within third-party cloud applications.

  • Microsoft Defender for Cloud Apps

    Why this is correct

    Microsoft Defender for Cloud Apps functions as a comprehensive Cloud Access Security Broker (CASB), providing deep visibility, robust control, and advanced threat protection for data across an organization's entire cloud application landscape, including both Microsoft and numerous third-party SaaS applications. It excels at discovering shadow IT, enforcing granular data loss prevention policies, and detecting anomalous user behavior or threats within these diverse cloud environments. Its capabilities are specifically tailored to monitor and secure interactions with external SaaS applications, making it the correct choice for this scenario.

  • Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud is a unified solution offering cloud security posture management (CSPM) and cloud workload protection (CWP) across multi-cloud and hybrid environments, including Azure, AWS, and GCP. It provides threat protection for IaaS and PaaS resources such as virtual machines, containers, databases, and storage, along with recommendations to improve overall security posture. However, its primary focus is on the underlying infrastructure and platform services, not the security monitoring or anomaly detection within third-party SaaS applications themselves.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.