Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Which TWO are features of Microsoft Defender for Cloud Apps? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse Defender for Cloud Apps with other Microsoft security products, mistakenly attributing features like email threat investigation (Defender for Office 365) or endpoint vulnerability management (Defender for Endpoint) to Cloud Apps, when the exam specifically tests Cloud Discovery and OAuth app governance as its unique capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Discovery to identify shadow IT

Option D (Cloud Discovery to identify shadow IT) is correct because Microsoft Defender for Cloud Apps includes Cloud Discovery, which analyzes traffic logs from firewalls and proxies (or uses the Defender for Endpoint integration) to detect unsanctioned cloud apps and produce a risk-ranked Cloud app catalog, directly addressing shadow IT. Option E (App governance for OAuth apps) is correct because Defender for Cloud Apps provides app governance capabilities that detect, alert on, and remediate risky or overprivileged OAuth applications and their permissions in Microsoft 365 and connected SaaS apps. Option A is not a Defender for Cloud Apps feature; sensitivity labels are applied through Microsoft Purview Information Protection (e.g., in Office apps and the Purview compliance portal), not by Defender for Cloud Apps. Option B is not correct because investigating email-borne attacks is the role of Microsoft Defender for Office 365 (its investigation and threat-explorer/attack-simulation capabilities), not Defender for Cloud Apps. Option C is not correct because endpoint vulnerability management is delivered by Microsoft Defender Vulnerability Management (part of Defender for Endpoint), not by Defender for Cloud Apps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply sensitivity labels to files

    Why it's wrong here

    Applying sensitivity labels to files is a core capability of Microsoft Purview Information Protection (formerly Azure Information Protection). While Microsoft Defender for Cloud Apps can detect and alert on sensitive data being uploaded or shared, and can integrate with Purview to enforce policies, it does not directly apply the labels itself. Its role is more about monitoring cloud app usage and data movement, not the direct classification and labeling of content.

  • ✗

    Investigate email-borne attacks

    Why it's wrong here

    Investigating email-borne attacks, such as phishing, malware, or spam delivered via email, is a primary function of Microsoft Defender for Office 365. This specialized solution provides advanced protection against email threats, including post-delivery investigation and remediation. Microsoft Defender for Cloud Apps focuses on securing cloud applications and the data within them, not the email transport layer.

  • ✗

    Vulnerability management for endpoints

    Why it's wrong here

    Vulnerability management for endpoints, including discovery, assessment, and remediation of software vulnerabilities and misconfigurations on devices, is a key feature of Microsoft Defender for Endpoint. This solution provides comprehensive endpoint detection and response (EDR) capabilities. Microsoft Defender for Cloud Apps, conversely, is designed to secure cloud applications and services, not the physical or virtual endpoints accessing them.

  • ✓

    Cloud Discovery to identify shadow IT

    Why this is correct

    Cloud Discovery is a fundamental feature of Microsoft Defender for Cloud Apps that identifies all cloud applications being used across an organization's network. By analyzing traffic logs from firewalls and proxies, it uncovers "shadow IT" – unsanctioned cloud apps – and provides risk assessments for each discovered application. This capability helps organizations gain visibility into their cloud app landscape and manage associated risks.

  • ✓

    App governance for OAuth apps

    Why this is correct

    App governance, a capability within Microsoft Defender for Cloud Apps, provides comprehensive visibility and control over OAuth-enabled applications connected to Microsoft 365 and other SaaS apps. It helps identify, alert on, and remediate risky or malicious app behaviors, such as over-privileged permissions or unusual data access patterns. This feature is crucial for managing the security posture of third-party applications integrated into the cloud environment.

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.