Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A security team wants to discover which cloud applications (such as Dropbox, Salesforce, or unsanctioned file-sharing apps) are being used by employees, even if those apps are not sanctioned by IT. They need to analyze usage patterns, risk levels, and identify potential shadow IT. Which feature of Microsoft Defender for Cloud Apps should they enable?

⚠ Common exam trap

Watch out — candidates often confuse Cloud Discovery (passive log analysis for unsanctioned apps) with App Connectors (active API integration for sanctioned apps), assuming both can discover shadow IT, but only Cloud Discovery identifies apps not already connected via API.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Cloud Discovery

Cloud Discovery is the correct feature because it analyzes traffic logs from firewalls and proxies to identify cloud app usage, including unsanctioned apps like Dropbox or Salesforce, without requiring API integration. It provides risk scores, usage patterns, and shadow IT detection by comparing discovered apps against Microsoft's cloud app catalog of over 31,000 apps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • App Connectors (API connectors)

    Why it's wrong here

    App Connectors, also known as API connectors in Microsoft Defender for Cloud Apps (MDCA), provide deep visibility and granular control over *sanctioned* cloud applications by integrating directly with their APIs. While crucial for enforcing policies and monitoring activity within *connected* apps, they are not designed to *discover* unknown or unsanctioned cloud applications (shadow IT) across an organization's network traffic. Their function presumes prior knowledge and configuration of the specific application.

  • Cloud Discovery

    Why this is correct

    Cloud Discovery, a core feature of Microsoft Defender for Cloud Apps (MDCA), is specifically designed to identify all cloud applications accessed by users within an organization. It achieves this by analyzing network traffic logs from firewalls, proxies, and other network devices, correlating IP addresses and URLs to known cloud services. This process provides a comprehensive overview of both sanctioned and unsanctioned "shadow IT" applications, which is precisely what a security team needs for initial discovery.

  • Conditional Access App Control

    Why it's wrong here

    Conditional Access App Control (CAAC) in Microsoft Defender for Cloud Apps (MDCA) acts as a reverse proxy to enforce real-time session policies for applications already integrated with Azure AD Conditional Access. It provides granular control over user actions within *sanctioned* cloud apps, such as preventing data downloads or enforcing label requirements. However, CAAC's purpose is policy enforcement and session monitoring for *managed* applications, not the initial identification or discovery of unknown or unsanctioned cloud services.

  • Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint (MDE) is an enterprise endpoint security platform that provides advanced threat protection, post-breach detection, automated investigation, and response capabilities for devices. While MDE can monitor network connections originating from endpoints and identify some cloud service interactions at the device level, its primary function is endpoint protection and incident response. It is not architected to provide a holistic, organization-wide inventory of all cloud applications accessed by all users, which is the goal of cloud app discovery.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.