SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company wants to gain visibility into the use of unsanctioned cloud applications (shadow IT) within their organization. The security team has access to network proxy logs that show traffic to various cloud services. They want to use a Microsoft security solution to analyze these logs and identify which cloud apps are being used, by whom, and how much data is being consumed. Which capability of Microsoft Defender for Cloud Apps should they use?
⚠ Common exam trap
Candidates often confuse Cloud Discovery (log analysis for shadow IT discovery) with App Connectors (API-based integration for managed apps), leading them to select App Connectors because they think 'connecting' to apps is needed to see usage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Discovery
Cloud Discovery in Microsoft Defender for Cloud Apps analyzes network proxy logs (or traffic logs from firewalls and proxies) to identify unsanctioned cloud app usage (shadow IT). It provides visibility into which cloud apps are being used, by which users, and how much data is consumed, directly matching the company's requirement to analyze logs for shadow IT detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
App governance
Why it's wrong here
App governance, a feature within Microsoft Defender for Cloud Apps, focuses on managing and monitoring OAuth-enabled applications that have already been granted permissions to Microsoft 365 data. Its primary function is to detect and alert on risky app behaviors, excessive permissions, or unusual data access patterns for *known* applications, rather than discovering previously unknown or unsanctioned cloud applications by analyzing network traffic logs.
When this WOULD be correct
A question asks: 'Which Microsoft Defender for Cloud Apps capability should an organization use to monitor and control app permissions for third-party OAuth apps connected to Microsoft 365?'
- ✓
Cloud Discovery
Why this is correct
Cloud Discovery, a core component of Microsoft Defender for Cloud Apps (MDCA), is specifically designed to analyze traffic logs from firewalls, proxies, and other network devices to identify all cloud applications accessed by users. This process enables organizations to gain comprehensive visibility into 'shadow IT' – unsanctioned cloud applications – and assess their associated risks, providing crucial insights into usage patterns across the environment.
- ✗
Conditional Access App Control
Why it's wrong here
Conditional Access App Control (CAAC) functions as a reverse proxy to provide real-time session monitoring and control over access to *sanctioned* cloud applications. It enforces policies like blocking downloads, preventing copy-paste, or requiring multi-factor authentication during a session, based on conditions defined in Azure AD Conditional Access. CAAC does not, however, perform the initial discovery of unsanctioned cloud applications from network logs; it operates on applications already known and configured for access control.
When this WOULD be correct
An exam scenario where an organization needs to enforce real-time access controls (e.g., block downloads or require multi-factor authentication) for specific cloud apps based on user or device conditions, using Microsoft Defender for Cloud Apps' reverse proxy capabilities.
- ✗
App Connectors
Why it's wrong here
App Connectors in Microsoft Defender for Cloud Apps provide direct, API-based integration with *sanctioned* cloud applications (e.g., Microsoft 365, Salesforce, Box) to gain deep visibility into activities, files, and accounts within those specific services. While they offer granular control and data protection for connected apps, App Connectors are not used for analyzing network traffic or proxy logs to discover unknown or unsanctioned cloud applications.
When this WOULD be correct
When a company needs to enforce policies and gain granular visibility into sanctioned cloud apps (e.g., Office 365, Salesforce) by connecting directly via APIs to monitor user activities, data, and compliance.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Cloud DiscoveryCorrect answer▾
Why this is correct
Cloud Discovery, a core component of Microsoft Defender for Cloud Apps (MDCA), is specifically designed to analyze traffic logs from firewalls, proxies, and other network devices to identify all cloud applications accessed by users. This process enables organizations to gain comprehensive visibility into 'shadow IT' – unsanctioned cloud applications – and assess their associated risks, providing crucial insights into usage patterns across the environment.
✗App governanceWrong answer — click to see why▾
Why this is wrong here
App governance focuses on managing and governing app permissions and policies for OAuth-enabled apps, not on analyzing network proxy logs to discover unsanctioned cloud app usage.
★ When this WOULD be the correct answer
A question asks: 'Which Microsoft Defender for Cloud Apps capability should an organization use to monitor and control app permissions for third-party OAuth apps connected to Microsoft 365?'
Why candidates choose this
Candidates may confuse 'governance' with 'discovery' because both involve monitoring cloud apps, but App governance is specifically for OAuth app permissions, not for identifying shadow IT from network logs.
✗Conditional Access App ControlWrong answer — click to see why▾
Why this is wrong here
Conditional Access App Control is used to enforce access policies on cloud apps in real-time, not to analyze proxy logs for discovering unsanctioned app usage. The question specifically requires analyzing network proxy logs to identify shadow IT, which is the function of Cloud Discovery.
★ When this WOULD be the correct answer
An exam scenario where an organization needs to enforce real-time access controls (e.g., block downloads or require multi-factor authentication) for specific cloud apps based on user or device conditions, using Microsoft Defender for Cloud Apps' reverse proxy capabilities.
Why candidates choose this
Candidates may confuse Conditional Access App Control with Cloud Discovery because both are features of Defender for Cloud Apps, and the term 'control' might seem related to managing unsanctioned apps, but the question asks for analysis, not enforcement.
✗App ConnectorsWrong answer — click to see why▾
Why this is wrong here
App Connectors are used to connect to specific cloud apps via APIs for deep visibility and control, not to analyze network proxy logs for discovering unsanctioned cloud apps.
★ When this WOULD be the correct answer
When a company needs to enforce policies and gain granular visibility into sanctioned cloud apps (e.g., Office 365, Salesforce) by connecting directly via APIs to monitor user activities, data, and compliance.
Why candidates choose this
Candidates may think 'App Connectors' is the right tool because it involves connecting to cloud apps, but they overlook that the question specifies analyzing network proxy logs for shadow IT discovery, which is Cloud Discovery's function.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.