Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company wants to gain visibility into the cloud applications that employees are using (e.g., unsanctioned SaaS apps), assess the risk level of each app based on multiple factors, and block access to high-risk applications. Which Microsoft security solution should they deploy?

⚠ Common exam trap

Many exam-takers confuse a CASB (Defender for Cloud Apps) with an EDR (Defender for Endpoint) or SIEM (Sentinel), as candidates often think 'visibility into apps' means endpoint monitoring or log analysis rather than cloud-specific app discovery and risk assessment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility into cloud application usage, assesses risk based on factors like compliance, app store ratings, and security controls, and can block access to high-risk apps via reverse proxy or API integration. This directly matches the requirement to discover unsanctioned SaaS apps and enforce access controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint is an Endpoint Detection and Response (EDR) solution focused on protecting endpoints such as workstations, servers, and mobile devices from cyber threats. It monitors device activity, detects malicious behaviors, and provides automated investigation and remediation capabilities directly on the endpoint. Although it can observe network connections originating from an endpoint, its primary function is not to identify, categorize, or manage the usage of diverse cloud applications themselves, nor does it offer CASB-like controls over them.

    When this WOULD be correct

    A company wants to protect its endpoints from malware, detect advanced attacks on devices, and investigate security incidents on workstations and servers. Which Microsoft security solution should they deploy?

  • Microsoft Defender for Office 365

    Why it's wrong here

    Microsoft Defender for Office 365 is specifically designed to protect an organization's Microsoft 365 services, including email (Exchange Online), Teams, SharePoint Online, and OneDrive for Business, from advanced threats like phishing, malware, and business email compromise. While it offers robust security and some visibility into activities within these specific Microsoft applications, it does not provide the broader discovery, risk assessment, or control capabilities for the full spectrum of third-party cloud applications used by employees across the entire network.

    When this WOULD be correct

    A company wants to protect against email-borne threats like phishing, malware, and business email compromise (BEC), and enforce policies for safe links and attachments in Office 365. In that scenario, Microsoft Defender for Office 365 is the correct solution.

  • Microsoft Defender for Cloud Apps

    Why this is correct

    Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing comprehensive visibility and control over cloud applications used across an organization. It automatically discovers all cloud apps, both sanctioned and unsanctioned (shadow IT), assesses their risk based on over 25,000 applications in its catalog, and enables granular policy enforcement for access, data protection, and threat prevention within these applications. This capability directly addresses the need to gain visibility into what cloud applications employees are utilizing.

  • Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that aggregates security data from various sources across an organization's environment. It is used for centralized log collection, threat detection, investigation, and automated response. While Sentinel can ingest logs and alerts *from* cloud applications or a CASB, it does not natively perform the discovery, risk assessment, or direct policy enforcement for cloud applications; it relies on other services to provide that foundational cloud app usage data.

    When this WOULD be correct

    An organization needs to centralize security event monitoring, correlate alerts from multiple sources (e.g., on-premises, cloud, identities), and automate incident response across their entire environment. In that scenario, Microsoft Sentinel would be the correct choice.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft Defender for Cloud AppsCorrect answer

Why this is correct

Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing comprehensive visibility and control over cloud applications used across an organization. It automatically discovers all cloud apps, both sanctioned and unsanctioned (shadow IT), assesses their risk based on over 25,000 applications in its catalog, and enables granular policy enforcement for access, data protection, and threat prevention within these applications. This capability directly addresses the need to gain visibility into what cloud applications employees are utilizing.

Microsoft Defender for EndpointWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Endpoint focuses on endpoint devices (e.g., desktops, servers) to prevent, detect, and respond to threats, not on discovering and controlling cloud application usage. It does not provide visibility into unsanctioned SaaS apps or allow blocking access based on app risk.

★ When this WOULD be the correct answer

A company wants to protect its endpoints from malware, detect advanced attacks on devices, and investigate security incidents on workstations and servers. Which Microsoft security solution should they deploy?

Why candidates choose this

Candidates may confuse 'endpoint' with 'cloud apps' or assume that all Microsoft security tools can monitor cloud usage, leading them to choose Defender for Endpoint without recognizing its device-centric scope.

Microsoft Defender for Office 365Wrong answer — click to see why

Why this is wrong here

Microsoft Defender for Office 365 focuses on securing email and collaboration tools (Exchange, SharePoint, Teams), not on discovering and controlling unsanctioned cloud app usage across the organization.

★ When this WOULD be the correct answer

A company wants to protect against email-borne threats like phishing, malware, and business email compromise (BEC), and enforce policies for safe links and attachments in Office 365. In that scenario, Microsoft Defender for Office 365 is the correct solution.

Why candidates choose this

Candidates may confuse the 'Defender' branding and assume all Defender products provide similar cloud app visibility, or they may think Office 365 covers all cloud apps because it includes cloud-based services.

Microsoft SentinelWrong answer — click to see why

Why this is wrong here

Microsoft Sentinel is a SIEM/SOAR solution for security analytics and threat intelligence across the enterprise, not specifically designed to discover, assess, and block unsanctioned cloud applications. The question focuses on cloud app visibility and control, which is the domain of Defender for Cloud Apps.

★ When this WOULD be the correct answer

An organization needs to centralize security event monitoring, correlate alerts from multiple sources (e.g., on-premises, cloud, identities), and automate incident response across their entire environment. In that scenario, Microsoft Sentinel would be the correct choice.

Why candidates choose this

Candidates may confuse Sentinel's broad security analytics capabilities with the specific cloud app discovery and control features of Defender for Cloud Apps, or they may think Sentinel can directly block cloud app access, which it cannot without integration.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.