Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company wants to gain visibility into which cloud applications are being used by employees (shadow IT) and assess the risk level of each app. They use Microsoft Defender for Cloud Apps. Which feature should they enable to discover and analyze these apps?

⚠ Common exam trap

A common mix-up: candidates confuse Cloud Discovery (which finds unknown apps via traffic analysis) with Conditional Access App Control (which controls access to known apps), leading them to pick Option C for a discovery question.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Cloud Discovery

Cloud Discovery is the correct feature because it analyzes traffic logs against the Microsoft Defender for Cloud Apps catalog of over 31,000 cloud apps to identify shadow IT usage. It provides risk scores based on factors like security certifications, data encryption, and compliance standards, enabling the company to assess each app's risk level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • App Governance

    Why it's wrong here

    App Governance, a capability within Microsoft Defender for Cloud Apps, focuses on monitoring, auditing, and governing OAuth-enabled applications that have been granted access to Microsoft 365 data. It helps manage app permissions, detect anomalous app behavior, and enforce policies on these *already connected* applications. However, it does not provide the initial discovery mechanism for identifying all unsanctioned cloud applications (shadow IT) being used across an organization's network.

  • Cloud Discovery

    Why this is correct

    Cloud Discovery, a core feature of Microsoft Defender for Cloud Apps, analyzes traffic logs from firewalls and proxy servers to identify all cloud applications accessed by users within an organization. It provides comprehensive visibility into both sanctioned and unsanctioned cloud services, often referred to as "shadow IT." This process helps security teams assess the risk associated with each discovered application and gain a complete understanding of cloud usage patterns.

  • Conditional Access App Control

    Why it's wrong here

    Conditional Access App Control, powered by Microsoft Defender for Cloud Apps, provides real-time monitoring and control over user sessions with cloud applications. It enforces session policies, such as blocking downloads or requiring re-authentication, *after* a user has successfully authenticated and a Conditional Access policy has been triggered. This capability focuses on governing behavior within *already accessed* applications, rather than discovering which applications are being used across the network in the first place.

  • OAuth app policies

    Why it's wrong here

    OAuth app policies are rules designed to manage and restrict the permissions granted by users to OAuth-enabled applications, typically within Microsoft 365 or Azure AD. These policies, often configured through App Governance, help prevent over-privileged apps or detect suspicious permission grants. While crucial for securing *known* applications and their access, they do not function as a mechanism for discovering unknown or unsanctioned cloud applications being used by employees.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.