SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A security team wants to discover which cloud applications (such as Dropbox, Salesforce, or unsanctioned file-sharing apps) are being used by employees, even if those apps are not sanctioned by IT. They need to analyze usage patterns, risk levels, and identify potential shadow IT. Which feature of Microsoft Defender for Cloud Apps should they enable?
⚠ Common exam trap
Watch out — candidates often confuse Cloud Discovery (passive log analysis for unsanctioned apps) with App Connectors (active API integration for sanctioned apps), assuming both can discover shadow IT, but only Cloud Discovery identifies apps not already connected via API.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Discovery
Cloud Discovery is the correct feature because it analyzes traffic logs from firewalls and proxies to identify cloud app usage, including unsanctioned apps like Dropbox or Salesforce, without requiring API integration. It provides risk scores, usage patterns, and shadow IT detection by comparing discovered apps against Microsoft's cloud app catalog of over 31,000 apps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
App Connectors (API connectors)
Why it's wrong here
App Connectors, also known as API connectors in Microsoft Defender for Cloud Apps (MDCA), provide deep visibility and granular control over *sanctioned* cloud applications by integrating directly with their APIs. While crucial for enforcing policies and monitoring activity within *connected* apps, they are not designed to *discover* unknown or unsanctioned cloud applications (shadow IT) across an organization's network traffic. Their function presumes prior knowledge and configuration of the specific application.
- ✓
Cloud Discovery
Why this is correct
Cloud Discovery, a core feature of Microsoft Defender for Cloud Apps (MDCA), is specifically designed to identify all cloud applications accessed by users within an organization. It achieves this by analyzing network traffic logs from firewalls, proxies, and other network devices, correlating IP addresses and URLs to known cloud services. This process provides a comprehensive overview of both sanctioned and unsanctioned "shadow IT" applications, which is precisely what a security team needs for initial discovery.
- ✗
Conditional Access App Control
Why it's wrong here
Conditional Access App Control (CAAC) in Microsoft Defender for Cloud Apps (MDCA) acts as a reverse proxy to enforce real-time session policies for applications already integrated with Azure AD Conditional Access. It provides granular control over user actions within *sanctioned* cloud apps, such as preventing data downloads or enforcing label requirements. However, CAAC's purpose is policy enforcement and session monitoring for *managed* applications, not the initial identification or discovery of unknown or unsanctioned cloud services.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Microsoft Defender for Endpoint (MDE) is an enterprise endpoint security platform that provides advanced threat protection, post-breach detection, automated investigation, and response capabilities for devices. While MDE can monitor network connections originating from endpoints and identify some cloud service interactions at the device level, its primary function is endpoint protection and incident response. It is not architected to provide a holistic, organization-wide inventory of all cloud applications accessed by all users, which is the goal of cloud app discovery.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.