Courseiva

SC-900 Shadow IT Discovery Practice Question

A company uses Microsoft 365 and many third-party SaaS apps like Salesforce and Box. The security team needs to discover which unsanctioned cloud apps employees are using (Shadow IT). They also want to get a risk score for each app and receive alerts when a high-risk app is used. Which Microsoft security solution should they use?

⚠ Common exam trap

It's easy for candidates to confuse Microsoft Defender for Cloud Apps with other Defender products (Endpoint or Identity) because they all share the 'Defender' branding, but only Cloud Apps provides CASB capabilities for Shadow IT discovery and app risk scoring.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps (MDCA) is the correct solution because it is specifically designed for Cloud Access Security Broker (CASB) functions, including Shadow IT discovery, risk scoring of cloud apps, and policy-based alerts. It integrates with Microsoft 365 and third-party SaaS apps via API connectors and log collectors to identify unsanctioned app usage and assign a risk score based on factors like compliance, security controls, and industry standards.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Endpoint

    Why it's wrong here

    Defender for Endpoint protects and investigates devices; it does not catalogue SaaS usage or assign cloud app risk scores. It is tempting because it is a Microsoft security workload that surfaces alerts. Defender for Cloud Apps performs Shadow IT discovery, risk scoring and high-risk app alerts.

  • ✗

    Microsoft Defender for Identity

    Why it's wrong here

    Defender for Identity monitors on-premises Active Directory signals for identity-based attacks; it cannot discover SaaS apps or assign them risk scores. It is tempting because it addresses identity threats, but that is the wrong axis here — Defender for Cloud Apps performs Shadow IT discovery via Cloud Discovery logs.

  • ✓

    Microsoft Defender for Cloud Apps

    Why this is correct

    Defender for Cloud Apps uses Cloud Discovery to analyse traffic logs against its app catalogue, surfacing unsanctioned Shadow IT usage. Its risk scoring and anomaly detection policies then alert on high-risk apps, directly meeting the discovery, scoring and alerting requirements for Salesforce, Box and similar SaaS services.

  • ✗

    Microsoft Purview Compliance Manager

    Why it's wrong here

    Compliance Manager assesses an organisation's compliance posture against regulations and tracks improvement actions; it neither discovers unsanctioned SaaS usage nor scores app risk. It is tempting because it reports on cloud governance, but that is the wrong axis — Defender for Cloud Apps performs Cloud Discovery and risk scoring.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.