SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which TWO are capabilities of Microsoft Defender for Cloud Apps? (Choose two.)
⚠ Common exam trap
Watch out — candidates often confuse the broad 'security solutions' umbrella and attribute endpoint or identity features to Defender for Cloud Apps, when in fact each Microsoft security product (Defender for Endpoint, Entra ID Protection, Purview) has a distinct scope and integration point.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session control to monitor user activity in cloud apps
Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides Cloud Discovery to identify shadow IT by analyzing traffic logs from firewalls and proxies, making option E correct. It also delivers Conditional Access App Control, which uses reverse-proxy session control to monitor and restrict user activity in cloud apps in real time, making option D correct. Option A is wrong because endpoint detection and response is provided by Microsoft Defender for Endpoint, not Defender for Cloud Apps. Option B is wrong because identity protection for user accounts is handled by Microsoft Entra ID Protection. Option C is wrong because data classification of on-premises files is performed by Microsoft Purview Information Protection, not by this CASB service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Endpoint detection and response (EDR)
Why it's wrong here
Endpoint detection and response (EDR) operates at the operating-system level to monitor and respond to threats on individual devices, whereas Microsoft Defender for Cloud Apps governs cloud application usage and data protection across SaaS environments. This option is tempting because EDR is a core component of Microsoft’s extended detection and response (XDR) suite, and it would be correct if the question targeted endpoint security rather than cloud app governance.
- ✗
Identity protection for user accounts
Why it's wrong here
Defender for Cloud Apps governs SaaS discovery, session controls, app governance and anomaly detection; identity protection for accounts belongs to Microsoft Entra ID Protection. It is tempting because Cloud Apps surfaces risky sign-ins and compromised accounts, but those alerts derive from Entra ID signals rather than being its own capability.
- ✗
Data classification of on-premises files
Why it's wrong here
Defender for Cloud Apps governs cloud app usage via API connectors and proxies; it cannot classify files sitting on on-premises file servers. It is tempting because it does inspect and classify data within sanctioned cloud services, which is its actual purpose.
- ✓
Session control to monitor user activity in cloud apps
Why this is correct
Conditional Access App Control proxies sessions through Defender for Cloud Apps, letting administrators monitor and block user activity within cloud apps in real time. This satisfies the requirement to control actions inside sanctioned apps, which API-based connectors alone cannot enforce.
- ✓
Cloud Discovery to identify shadow IT
Why this is correct
Cloud Discovery analyses traffic logs from firewalls and proxies to catalogue which cloud apps employees use, exposing unsanctioned shadow IT. This satisfies the requirement to identify unapproved apps, enabling risk assessment and governance decisions before access is sanctioned.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
Data classification
Data classification is the process of organizing data into categories based on its sensitivity, value, and criticality to an organization, so that appropriate security controls can be applied.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.