SC-900 Shadow IT Discovery Practice Question
A company uses Microsoft 365 and many third-party SaaS apps like Salesforce and Box. The security team needs to discover which unsanctioned cloud apps employees are using (Shadow IT). They also want to get a risk score for each app and receive alerts when a high-risk app is used. Which Microsoft security solution should they use?
⚠ Common exam trap
It's easy for candidates to confuse Microsoft Defender for Cloud Apps with other Defender products (Endpoint or Identity) because they all share the 'Defender' branding, but only Cloud Apps provides CASB capabilities for Shadow IT discovery and app risk scoring.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps (MDCA) is the correct solution because it is specifically designed for Cloud Access Security Broker (CASB) functions, including Shadow IT discovery, risk scoring of cloud apps, and policy-based alerts. It integrates with Microsoft 365 and third-party SaaS apps via API connectors and log collectors to identify unsanctioned app usage and assign a risk score based on factors like compliance, security controls, and industry standards.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Defender for Endpoint protects and investigates devices; it does not catalogue SaaS usage or assign cloud app risk scores. It is tempting because it is a Microsoft security workload that surfaces alerts. Defender for Cloud Apps performs Shadow IT discovery, risk scoring and high-risk app alerts.
- ✗
Microsoft Defender for Identity
Why it's wrong here
Defender for Identity monitors on-premises Active Directory signals for identity-based attacks; it cannot discover SaaS apps or assign them risk scores. It is tempting because it addresses identity threats, but that is the wrong axis here — Defender for Cloud Apps performs Shadow IT discovery via Cloud Discovery logs.
- ✓
Microsoft Defender for Cloud Apps
Why this is correct
Defender for Cloud Apps uses Cloud Discovery to analyse traffic logs against its app catalogue, surfacing unsanctioned Shadow IT usage. Its risk scoring and anomaly detection policies then alert on high-risk apps, directly meeting the discovery, scoring and alerting requirements for Salesforce, Box and similar SaaS services.
- ✗
Microsoft Purview Compliance Manager
Why it's wrong here
Compliance Manager assesses an organisation's compliance posture against regulations and tracks improvement actions; it neither discovers unsanctioned SaaS usage nor scores app risk. It is tempting because it reports on cloud governance, but that is the wrong axis — Defender for Cloud Apps performs Cloud Discovery and risk scoring.
Go deeper
Related to this question
Learn chapter
Azure Policy for Compliance
Key term
Risk score
A risk score is a numerical value that represents the level of risk associated with a given asset, threat, or vulnerability in a security context.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.