Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A large enterprise uses a variety of cloud applications, including sanctioned apps like Microsoft 365 and unsanctioned apps that employees adopted without IT approval. The security team wants to discover all cloud applications in use, assess each app's risk score based on more than 80 risk factors, and control data sharing within sanctioned apps to prevent data leakage. Additionally, they need to identify which users are using a new, unknown file-sharing service. Which Microsoft security solution should be deployed to meet these requirements?

⚠ Common exam trap

It's easy for candidates to confuse Microsoft Defender for Cloud (a CSPM tool for Azure) with Microsoft Defender for Cloud Apps (a CASB), or they assume that Purview DLP alone can discover and risk-assess unsanctioned apps, when in fact DLP only controls data after the app is already identified and integrated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security) is a Cloud Access Security Broker (CASB) that provides visibility into both sanctioned and unsanctioned cloud apps through its Cloud Discovery feature. It assesses risk scores based on over 80 risk factors (e.g., encryption standards, data residency, and compliance certifications) and enables data sharing controls via session policies (e.g., Conditional Access App Control) to prevent data leakage. It also supports anomaly detection to identify users of new, unknown file-sharing services by analyzing traffic logs from network appliances or endpoints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud provides Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) capabilities across multi-cloud and hybrid environments. It focuses on strengthening the security posture of cloud resources like virtual machines, containers, databases, and storage accounts, and offers threat protection for these workloads. However, its primary scope is securing the underlying cloud infrastructure and services, not the discovery, risk assessment, or governance of third-party SaaS applications or shadow IT.

    When this WOULD be correct

    A question asking for a solution to assess and improve the security posture of Azure resources (e.g., virtual machines, storage accounts) by identifying misconfigurations, enabling compliance standards, and providing threat detection for cloud workloads. For example: 'Which Microsoft solution should be used to continuously monitor and improve the security of Azure VMs and storage accounts?'

  • Microsoft Defender for Cloud Apps

    Why this is correct

    Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security or MCAS) functions as a Cloud Access Security Broker (CASB). It provides comprehensive visibility into cloud applications, both sanctioned and unsanctioned (shadow IT), across an organization's network. By leveraging traffic logs from firewalls and proxies, it discovers all cloud apps, assesses their risk based on over 80 factors, and enables granular control over data and user activities within sanctioned applications to enforce security policies and prevent data leakage. This makes it ideal for managing the security posture of cloud app usage.

  • Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint is an enterprise endpoint security platform designed to protect devices such as workstations, servers, and mobile devices from advanced threats. It provides capabilities like endpoint detection and response (EDR), vulnerability management, and next-generation antivirus. While crucial for device security, its primary function is not to discover or assess the risk of cloud applications used by an organization, nor does it provide CASB functionalities for cloud app governance.

    When this WOULD be correct

    An exam question asking for a solution to detect and respond to advanced threats on endpoints (e.g., malware, ransomware) and investigate compromised devices would make Defender for Endpoint the correct answer.

  • Microsoft Purview Data Loss Prevention (DLP)

    Why it's wrong here

    Microsoft Purview Data Loss Prevention (DLP) solutions are designed to identify, monitor, and protect sensitive information across various locations, including Microsoft 365 services, endpoints, and on-premises repositories. While DLP policies can prevent the unauthorized sharing or exfiltration of sensitive data, its core purpose is data protection, not the discovery of unsanctioned cloud applications (shadow IT) or the comprehensive risk assessment of an organization's entire cloud app ecosystem. It operates on data content, not app discovery or risk scoring.

    When this WOULD be correct

    Microsoft Purview DLP would be correct in a scenario where an organization needs to prevent accidental sharing of sensitive data (e.g., credit card numbers or PII) across sanctioned apps like Microsoft 365 and endpoints, without requiring cloud app discovery or risk scoring. For example: 'A company wants to block emails containing social security numbers from being sent externally.'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft Defender for Cloud AppsCorrect answer

Why this is correct

Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security or MCAS) functions as a Cloud Access Security Broker (CASB). It provides comprehensive visibility into cloud applications, both sanctioned and unsanctioned (shadow IT), across an organization's network. By leveraging traffic logs from firewalls and proxies, it discovers all cloud apps, assesses their risk based on over 80 factors, and enables granular control over data and user activities within sanctioned applications to enforce security policies and prevent data leakage. This makes it ideal for managing the security posture of cloud app usage.

Microsoft Defender for CloudWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection solution, not designed to discover cloud apps, assess risk scores, or control data sharing across sanctioned and unsanctioned apps. It focuses on securing cloud infrastructure (e.g., VMs, databases) rather than SaaS application governance.

★ When this WOULD be the correct answer

A question asking for a solution to assess and improve the security posture of Azure resources (e.g., virtual machines, storage accounts) by identifying misconfigurations, enabling compliance standards, and providing threat detection for cloud workloads. For example: 'Which Microsoft solution should be used to continuously monitor and improve the security of Azure VMs and storage accounts?'

Why candidates choose this

The name 'Defender for Cloud' suggests it covers all cloud security needs, leading candidates to assume it includes app discovery and risk assessment. The lack of familiarity with the specific capabilities of Microsoft Defender for Cloud Apps (formerly Cloud App Security) causes confusion.

Microsoft Defender for EndpointWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Endpoint focuses on endpoint protection (antivirus, EDR) and does not provide cloud app discovery, risk assessment, or control over data sharing in cloud applications like Microsoft 365.

★ When this WOULD be the correct answer

An exam question asking for a solution to detect and respond to advanced threats on endpoints (e.g., malware, ransomware) and investigate compromised devices would make Defender for Endpoint the correct answer.

Why candidates choose this

Candidates may confuse Defender for Endpoint with Defender for Cloud Apps because both have 'Defender' in the name and relate to security, but they serve different domains (endpoints vs. cloud apps).

Microsoft Purview Data Loss Prevention (DLP)Wrong answer — click to see why

Why this is wrong here

Microsoft Purview Data Loss Prevention (DLP) focuses on preventing data leakage by enforcing policies on sensitive data, but it does not discover cloud applications, assess risk scores, or identify users of unsanctioned apps. The question requires cloud app discovery and risk assessment, which are capabilities of Defender for Cloud Apps, not DLP.

★ When this WOULD be the correct answer

Microsoft Purview DLP would be correct in a scenario where an organization needs to prevent accidental sharing of sensitive data (e.g., credit card numbers or PII) across sanctioned apps like Microsoft 365 and endpoints, without requiring cloud app discovery or risk scoring. For example: 'A company wants to block emails containing social security numbers from being sent externally.'

Why candidates choose this

Candidates may confuse DLP's data protection capabilities with the broader cloud app security requirements, especially since the question mentions controlling data sharing within sanctioned apps, which is a DLP function. However, they overlook that the primary need is discovery and risk assessment, which DLP does not provide.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.