SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company uses Salesforce and Box as cloud apps. The security team discovers that a third-party OAuth app with excessive permissions was granted access to Salesforce data by a user. They want a solution that can detect such risky OAuth apps and automatically revoke their permissions based on policy. Which Microsoft security solution provides this capability?
⚠ Common exam trap
Many exam-takers confuse Microsoft Defender for Cloud Apps with Microsoft Defender for Office 365, assuming the latter covers all cloud app security, when in reality MDCA is the dedicated CASB for multi-SaaS environments like Salesforce and Box.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps (MDCA) is a Cloud Access Security Broker (CASB) that provides visibility into third-party OAuth apps connected to cloud services like Salesforce and Box. It can detect OAuth apps with excessive permissions and automatically revoke them based on conditional access or app governance policies, making it the correct solution for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Cloud Apps
Why this is correct
Microsoft Defender for Cloud Apps (MDCAS) is the correct solution because it provides comprehensive visibility and control over cloud applications, including the discovery and assessment of OAuth-connected apps. It can identify risky OAuth apps that users have authorized to access data in connected cloud services like Salesforce and Box. Through its robust policy engine, MDCAS enables organizations to define and enforce granular policies, automatically revoking permissions for high-risk or non-compliant OAuth applications, thereby mitigating potential data exfiltration or unauthorized access risks.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Microsoft Defender for Endpoint (MDE) is incorrect because its primary function is to protect devices, such as workstations, servers, and mobile devices, from advanced threats like malware, ransomware, and fileless attacks. MDE provides capabilities such as endpoint detection and response (EDR), vulnerability management, and attack surface reduction. However, it does not extend its protection to govern or manage the permissions granted to third-party OAuth applications within cloud Software-as-a-Service (SaaS) platforms like Salesforce or Box.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 (MDO) is not the appropriate solution as it specializes in protecting an organization's Microsoft 365 environment from sophisticated threats. Its capabilities include safeguarding against phishing, spam, malware, and business email compromise across email (Exchange Online), collaboration tools (Teams), and document repositories (SharePoint Online, OneDrive for Business). MDO's scope is specifically limited to Microsoft 365 services and does not provide visibility or control over third-party cloud applications such as Salesforce or Box, nor does it manage their OAuth app permissions.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is an incorrect choice because it functions as a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. While Sentinel can ingest security logs and alerts from a vast array of sources, including cloud applications, to detect threats and automate responses, it primarily provides visibility and analytical capabilities. It does not possess the inherent functionality to directly discover, assess, or enforce policies for OAuth application permissions within connected SaaS platforms; rather, it would rely on data fed from a solution like Defender for Cloud Apps to identify such risks.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Defender for Cloud
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides unified security management and threat protection across hybrid and multi-cloud environments.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.