SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company wants to gain visibility into which cloud applications are being used by employees (shadow IT) and assess the risk level of each app. They use Microsoft Defender for Cloud Apps. Which feature should they enable to discover and analyze these apps?
⚠ Common exam trap
A common mix-up: candidates confuse Cloud Discovery (which finds unknown apps via traffic analysis) with Conditional Access App Control (which controls access to known apps), leading them to pick Option C for a discovery question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Discovery
Cloud Discovery is the correct feature because it analyzes traffic logs against the Microsoft Defender for Cloud Apps catalog of over 31,000 cloud apps to identify shadow IT usage. It provides risk scores based on factors like security certifications, data encryption, and compliance standards, enabling the company to assess each app's risk level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
App Governance
Why it's wrong here
App Governance, a capability within Microsoft Defender for Cloud Apps, focuses on monitoring, auditing, and governing OAuth-enabled applications that have been granted access to Microsoft 365 data. It helps manage app permissions, detect anomalous app behavior, and enforce policies on these *already connected* applications. However, it does not provide the initial discovery mechanism for identifying all unsanctioned cloud applications (shadow IT) being used across an organization's network.
- ✓
Cloud Discovery
Why this is correct
Cloud Discovery, a core feature of Microsoft Defender for Cloud Apps, analyzes traffic logs from firewalls and proxy servers to identify all cloud applications accessed by users within an organization. It provides comprehensive visibility into both sanctioned and unsanctioned cloud services, often referred to as "shadow IT." This process helps security teams assess the risk associated with each discovered application and gain a complete understanding of cloud usage patterns.
- ✗
Conditional Access App Control
Why it's wrong here
Conditional Access App Control, powered by Microsoft Defender for Cloud Apps, provides real-time monitoring and control over user sessions with cloud applications. It enforces session policies, such as blocking downloads or requiring re-authentication, *after* a user has successfully authenticated and a Conditional Access policy has been triggered. This capability focuses on governing behavior within *already accessed* applications, rather than discovering which applications are being used across the network in the first place.
- ✗
OAuth app policies
Why it's wrong here
OAuth app policies are rules designed to manage and restrict the permissions granted by users to OAuth-enabled applications, typically within Microsoft 365 or Azure AD. These policies, often configured through App Governance, help prevent over-privileged apps or detect suspicious permission grants. While crucial for securing *known* applications and their access, they do not function as a mechanism for discovering unknown or unsanctioned cloud applications being used by employees.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.