SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which TWO are capabilities of Microsoft Defender for Cloud Apps? (Choose two.)
⚠ Common exam trap
Watch out — candidates often confuse the broad 'security solutions' umbrella and attribute endpoint or identity features to Defender for Cloud Apps, when in fact each Microsoft security product (Defender for Endpoint, Entra ID Protection, Purview) has a distinct scope and integration point.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session control to monitor user activity in cloud apps
Microsoft Defender for Cloud Apps includes session control capabilities, which allow administrators to monitor and control user activity in real time within cloud applications. This is achieved through reverse proxy integration, enabling granular access policies and data loss prevention (DLP) actions during active sessions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Endpoint detection and response (EDR)
Why it's wrong here
Endpoint detection and response (EDR) operates at the operating-system level to monitor and respond to threats on individual devices, whereas Microsoft Defender for Cloud Apps governs cloud application usage and data protection across SaaS environments. This option is tempting because EDR is a core component of Microsoft’s extended detection and response (XDR) suite, and it would be correct if the question targeted endpoint security rather than cloud app governance.
- ✗
Identity protection for user accounts
Why it's wrong here
Identity protection is a Microsoft Entra ID capability.
- ✗
Data classification of on-premises files
Why it's wrong here
Data classification is a Microsoft Purview capability.
- ✓
Session control to monitor user activity in cloud apps
Why this is correct
Session control allows real-time monitoring and control of app sessions.
- ✓
Cloud Discovery to identify shadow IT
Why this is correct
Cloud Discovery discovers cloud apps in use.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Defender for Cloud Apps
Defender for Cloud Apps is a Microsoft cloud access security broker (CASB) that helps you discover, protect, and govern your cloud applications and data across multiple cloud environments.
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.