SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A large enterprise uses a variety of cloud applications, including sanctioned apps like Microsoft 365 and unsanctioned apps that employees adopted without IT approval. The security team wants to discover all cloud applications in use, assess each app's risk score based on more than 80 risk factors, and control data sharing within sanctioned apps to prevent data leakage. Additionally, they need to identify which users are using a new, unknown file-sharing service. Which Microsoft security solution should be deployed to meet these requirements?
⚠ Common exam trap
It's easy for candidates to confuse Microsoft Defender for Cloud (a CSPM tool for Azure) with Microsoft Defender for Cloud Apps (a CASB), or they assume that Purview DLP alone can discover and risk-assess unsanctioned apps, when in fact DLP only controls data after the app is already identified and integrated.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security) is a Cloud Access Security Broker (CASB) that provides visibility into both sanctioned and unsanctioned cloud apps through its Cloud Discovery feature. It assesses risk scores based on over 80 risk factors (e.g., encryption standards, data residency, and compliance certifications) and enables data sharing controls via session policies (e.g., Conditional Access App Control) to prevent data leakage. It also supports anomaly detection to identify users of new, unknown file-sharing services by analyzing traffic logs from network appliances or endpoints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud provides Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) capabilities across multi-cloud and hybrid environments. It focuses on strengthening the security posture of cloud resources like virtual machines, containers, databases, and storage accounts, and offers threat protection for these workloads. However, its primary scope is securing the underlying cloud infrastructure and services, not the discovery, risk assessment, or governance of third-party SaaS applications or shadow IT.
When this WOULD be correct
A question asking for a solution to assess and improve the security posture of Azure resources (e.g., virtual machines, storage accounts) by identifying misconfigurations, enabling compliance standards, and providing threat detection for cloud workloads. For example: 'Which Microsoft solution should be used to continuously monitor and improve the security of Azure VMs and storage accounts?'
- ✓
Microsoft Defender for Cloud Apps
Why this is correct
Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security or MCAS) functions as a Cloud Access Security Broker (CASB). It provides comprehensive visibility into cloud applications, both sanctioned and unsanctioned (shadow IT), across an organization's network. By leveraging traffic logs from firewalls and proxies, it discovers all cloud apps, assesses their risk based on over 80 factors, and enables granular control over data and user activities within sanctioned applications to enforce security policies and prevent data leakage. This makes it ideal for managing the security posture of cloud app usage.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Microsoft Defender for Endpoint is an enterprise endpoint security platform designed to protect devices such as workstations, servers, and mobile devices from advanced threats. It provides capabilities like endpoint detection and response (EDR), vulnerability management, and next-generation antivirus. While crucial for device security, its primary function is not to discover or assess the risk of cloud applications used by an organization, nor does it provide CASB functionalities for cloud app governance.
When this WOULD be correct
An exam question asking for a solution to detect and respond to advanced threats on endpoints (e.g., malware, ransomware) and investigate compromised devices would make Defender for Endpoint the correct answer.
- ✗
Microsoft Purview Data Loss Prevention (DLP)
Why it's wrong here
Microsoft Purview Data Loss Prevention (DLP) solutions are designed to identify, monitor, and protect sensitive information across various locations, including Microsoft 365 services, endpoints, and on-premises repositories. While DLP policies can prevent the unauthorized sharing or exfiltration of sensitive data, its core purpose is data protection, not the discovery of unsanctioned cloud applications (shadow IT) or the comprehensive risk assessment of an organization's entire cloud app ecosystem. It operates on data content, not app discovery or risk scoring.
When this WOULD be correct
Microsoft Purview DLP would be correct in a scenario where an organization needs to prevent accidental sharing of sensitive data (e.g., credit card numbers or PII) across sanctioned apps like Microsoft 365 and endpoints, without requiring cloud app discovery or risk scoring. For example: 'A company wants to block emails containing social security numbers from being sent externally.'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Defender for Cloud AppsCorrect answer▾
Why this is correct
Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security or MCAS) functions as a Cloud Access Security Broker (CASB). It provides comprehensive visibility into cloud applications, both sanctioned and unsanctioned (shadow IT), across an organization's network. By leveraging traffic logs from firewalls and proxies, it discovers all cloud apps, assesses their risk based on over 80 factors, and enables granular control over data and user activities within sanctioned applications to enforce security policies and prevent data leakage. This makes it ideal for managing the security posture of cloud app usage.
✗Microsoft Defender for CloudWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection solution, not designed to discover cloud apps, assess risk scores, or control data sharing across sanctioned and unsanctioned apps. It focuses on securing cloud infrastructure (e.g., VMs, databases) rather than SaaS application governance.
★ When this WOULD be the correct answer
A question asking for a solution to assess and improve the security posture of Azure resources (e.g., virtual machines, storage accounts) by identifying misconfigurations, enabling compliance standards, and providing threat detection for cloud workloads. For example: 'Which Microsoft solution should be used to continuously monitor and improve the security of Azure VMs and storage accounts?'
Why candidates choose this
The name 'Defender for Cloud' suggests it covers all cloud security needs, leading candidates to assume it includes app discovery and risk assessment. The lack of familiarity with the specific capabilities of Microsoft Defender for Cloud Apps (formerly Cloud App Security) causes confusion.
✗Microsoft Defender for EndpointWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Endpoint focuses on endpoint protection (antivirus, EDR) and does not provide cloud app discovery, risk assessment, or control over data sharing in cloud applications like Microsoft 365.
★ When this WOULD be the correct answer
An exam question asking for a solution to detect and respond to advanced threats on endpoints (e.g., malware, ransomware) and investigate compromised devices would make Defender for Endpoint the correct answer.
Why candidates choose this
Candidates may confuse Defender for Endpoint with Defender for Cloud Apps because both have 'Defender' in the name and relate to security, but they serve different domains (endpoints vs. cloud apps).
✗Microsoft Purview Data Loss Prevention (DLP)Wrong answer — click to see why▾
Why this is wrong here
Microsoft Purview Data Loss Prevention (DLP) focuses on preventing data leakage by enforcing policies on sensitive data, but it does not discover cloud applications, assess risk scores, or identify users of unsanctioned apps. The question requires cloud app discovery and risk assessment, which are capabilities of Defender for Cloud Apps, not DLP.
★ When this WOULD be the correct answer
Microsoft Purview DLP would be correct in a scenario where an organization needs to prevent accidental sharing of sensitive data (e.g., credit card numbers or PII) across sanctioned apps like Microsoft 365 and endpoints, without requiring cloud app discovery or risk scoring. For example: 'A company wants to block emails containing social security numbers from being sent externally.'
Why candidates choose this
Candidates may confuse DLP's data protection capabilities with the broader cloud app security requirements, especially since the question mentions controlling data sharing within sanctioned apps, which is a DLP function. However, they overlook that the primary need is discovery and risk assessment, which DLP does not provide.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.