SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which THREE capabilities are provided by Microsoft Defender for Cloud Apps? (Choose three.)
⚠ Common exam trap
It's easy for candidates to confuse the overlapping capabilities of Microsoft security products—specifically, they may incorrectly associate email scanning (Defender for Office 365) or endpoint detection (Defender for Endpoint) with Defender for Cloud Apps, which is strictly a CASB focused on cloud app discovery, threat detection, and information protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat detection to identify malicious behavior in cloud apps
Option A is correct because Microsoft Defender for Cloud Apps (MDA) includes anomaly detection and threat detection policies that use Microsoft's threat intelligence and user behavior analytics to identify malicious activity, compromised accounts, and risky user behavior across cloud applications. Option B is correct because Cloud Discovery is a core MDA capability that analyzes traffic logs (from firewalls, proxies, or Defender for Endpoint) against the Cloud App Catalog to detect shadow IT and assess app risk. Option E is correct because MDA integrates with Microsoft Purview Information Protection to classify and apply sensitivity labels to files stored in supported cloud apps, enabling data protection and DLP enforcement. Option C is not correct because email scanning and remediation is handled by Microsoft Defender for Office 365, not MDA. Option D is not correct because endpoint detection and response is provided by Microsoft Defender for Endpoint, not MDA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Threat detection to identify malicious behavior in cloud apps
Why this is correct
Microsoft Defender for Cloud Apps provides robust threat detection by continuously monitoring user and entity behavior across connected cloud applications. It leverages advanced analytics and machine learning to identify anomalous activities, such as impossible travel, unusual data downloads, or suspicious administrative actions, which could indicate a compromised account or insider threat. This capability offers real-time alerts and automated remediation to protect against malicious behavior within the cloud app environment.
- ✓
Cloud Discovery to identify shadow IT
Why this is correct
Cloud Discovery is a core capability of Microsoft Defender for Cloud Apps designed to identify 'shadow IT' within an organization. It achieves this by analyzing traffic logs from firewalls and proxy servers to discover all cloud applications accessed by users. This process provides administrators with comprehensive visibility into the cloud app landscape, allowing them to assess risk, sanction or unsanction applications, and enforce policies to manage unsanctioned app usage.
- ✗
Email scanning and remediation
Why it's wrong here
Email scanning and remediation, including advanced anti-phishing, anti-spam, and malware protection for email, are primary functions of Microsoft Defender for Office 365 (MDO). While MDO is part of the broader Microsoft Defender suite, its specific focus is on protecting email, SharePoint, OneDrive, and Teams from sophisticated threats. This capability is distinct from the core offerings of Microsoft Defender for Cloud Apps, which primarily secures SaaS applications and their data.
- ✗
Endpoint detection and response (EDR)
Why it's wrong here
Endpoint Detection and Response (EDR) is a specialized security capability provided by Microsoft Defender for Endpoint (MDE). MDE focuses on protecting devices such as workstations, servers, and mobile devices by continuously monitoring their activity, detecting advanced threats, and providing automated investigation and response capabilities directly on the endpoint. This is distinct from the cloud application security focus of Microsoft Defender for Cloud Apps.
- ✓
Information protection to apply labels to files stored in cloud apps
Why this is correct
Microsoft Defender for Cloud Apps integrates with Microsoft Purview Information Protection to provide robust information protection capabilities. It can automatically scan files stored in connected cloud applications for sensitive content based on predefined policies. Upon detection, it can apply or modify sensitivity labels to these files, ensuring consistent data classification, enforcing data loss prevention (DLP) policies, and maintaining compliance across cloud storage.
Go deeper
Related to this question
Learn chapter
Defender for Endpoint Onboarding
Key term
Labels
Labels are descriptive text or tags attached to IT resources to organize, identify, and manage them based on attributes like purpose, environment, or owner.
Key term
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint is a cloud-delivered enterprise-grade security platform that protects devices, servers, and networks from advanced cyber threats by combining antivirus, endpoint detection and response, and automated investigation and remediation.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.