Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Which THREE capabilities are provided by Microsoft Defender for Cloud Apps? (Choose three.)

⚠ Common exam trap

It's easy for candidates to confuse the overlapping capabilities of Microsoft security products—specifically, they may incorrectly associate email scanning (Defender for Office 365) or endpoint detection (Defender for Endpoint) with Defender for Cloud Apps, which is strictly a CASB focused on cloud app discovery, threat detection, and information protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Threat detection to identify malicious behavior in cloud apps

Option A is correct because Microsoft Defender for Cloud Apps (MDA) includes anomaly detection and threat detection policies that use Microsoft's threat intelligence and user behavior analytics to identify malicious activity, compromised accounts, and risky user behavior across cloud applications. Option B is correct because Cloud Discovery is a core MDA capability that analyzes traffic logs (from firewalls, proxies, or Defender for Endpoint) against the Cloud App Catalog to detect shadow IT and assess app risk. Option E is correct because MDA integrates with Microsoft Purview Information Protection to classify and apply sensitivity labels to files stored in supported cloud apps, enabling data protection and DLP enforcement. Option C is not correct because email scanning and remediation is handled by Microsoft Defender for Office 365, not MDA. Option D is not correct because endpoint detection and response is provided by Microsoft Defender for Endpoint, not MDA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Threat detection to identify malicious behavior in cloud apps

    Why this is correct

    Microsoft Defender for Cloud Apps provides robust threat detection by continuously monitoring user and entity behavior across connected cloud applications. It leverages advanced analytics and machine learning to identify anomalous activities, such as impossible travel, unusual data downloads, or suspicious administrative actions, which could indicate a compromised account or insider threat. This capability offers real-time alerts and automated remediation to protect against malicious behavior within the cloud app environment.

  • ✓

    Cloud Discovery to identify shadow IT

    Why this is correct

    Cloud Discovery is a core capability of Microsoft Defender for Cloud Apps designed to identify 'shadow IT' within an organization. It achieves this by analyzing traffic logs from firewalls and proxy servers to discover all cloud applications accessed by users. This process provides administrators with comprehensive visibility into the cloud app landscape, allowing them to assess risk, sanction or unsanction applications, and enforce policies to manage unsanctioned app usage.

  • ✗

    Email scanning and remediation

    Why it's wrong here

    Email scanning and remediation, including advanced anti-phishing, anti-spam, and malware protection for email, are primary functions of Microsoft Defender for Office 365 (MDO). While MDO is part of the broader Microsoft Defender suite, its specific focus is on protecting email, SharePoint, OneDrive, and Teams from sophisticated threats. This capability is distinct from the core offerings of Microsoft Defender for Cloud Apps, which primarily secures SaaS applications and their data.

  • ✗

    Endpoint detection and response (EDR)

    Why it's wrong here

    Endpoint Detection and Response (EDR) is a specialized security capability provided by Microsoft Defender for Endpoint (MDE). MDE focuses on protecting devices such as workstations, servers, and mobile devices by continuously monitoring their activity, detecting advanced threats, and providing automated investigation and response capabilities directly on the endpoint. This is distinct from the cloud application security focus of Microsoft Defender for Cloud Apps.

  • ✓

    Information protection to apply labels to files stored in cloud apps

    Why this is correct

    Microsoft Defender for Cloud Apps integrates with Microsoft Purview Information Protection to provide robust information protection capabilities. It can automatically scan files stored in connected cloud applications for sensitive content based on predefined policies. Upon detection, it can apply or modify sensitivity labels to these files, ensuring consistent data classification, enforcing data loss prevention (DLP) policies, and maintaining compliance across cloud storage.

Go deeper

Related to this question

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.