SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which TWO of the following are capabilities of Microsoft Defender for Cloud Apps? (Select TWO.)
⚠ Common exam trap
Many candidates confuse the integrated capabilities (like classification via Purview or device compliance via Intune) with Defender for Cloud Apps' native features, leading them to select options that describe adjacent Microsoft security solutions rather than Defender for Cloud Apps' core functionalities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Control access with Conditional Access App Control
Option C is correct because Defender for Cloud Apps provides Conditional Access App Control, which uses reverse-proxy deployment to enforce session policies (such as block download, block copy/paste, and require MFA) in real time for cloud apps, integrating with Microsoft Entra Conditional Access. Option E is correct because Cloud Discovery in Defender for Cloud Apps analyzes traffic logs from firewalls and proxies to identify shadow IT, risk-rate discovered apps against the Cloud App Catalog, and surface usage and compliance insights. Option A is not a Defender for Cloud Apps capability; device compliance policies are enforced by Microsoft Intune and evaluated by Microsoft Entra Conditional Access. Option B is not correct because threat analytics reports are a Microsoft Defender XDR/Defender for Endpoint feature, not a Defender for Cloud Apps capability. Option D is not correct because sensitive data classification across cloud apps is performed by Microsoft Purview Information Protection and data classification services, not by Defender for Cloud Apps itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enforce device compliance policies
Why it's wrong here
Enforcing device compliance policies is primarily a function of Microsoft Intune, which assesses device health and configuration against defined standards. Conditional Access then leverages these compliance signals to determine access to resources. While Microsoft Defender for Cloud Apps (MDCA) can integrate with Conditional Access to apply session controls based on device compliance, MDCA itself does not manage or enforce the device's compliance posture directly.
- ✗
Provide threat analytics reports
Why it's wrong here
Providing comprehensive threat analytics reports, which offer expert-backed insights into active threats, vulnerabilities, and recommended actions, is a core capability of Microsoft 365 Defender, particularly driven by Defender for Endpoint and Defender for Office 365. While Microsoft Defender for Cloud Apps (MDCA) generates alerts and reports on anomalous activities and risks within cloud applications, it does not provide the broad, proactive threat intelligence and deep dive analysis characteristic of dedicated threat analytics.
- ✓
Control access with Conditional Access App Control
Why this is correct
Microsoft Defender for Cloud Apps (MDCA) provides Conditional Access App Control, which enables real-time monitoring and control over user sessions to cloud applications. By integrating with Microsoft Entra Conditional Access policies, MDCA can enforce session-specific controls, such as blocking downloads, requiring step-up authentication, or protecting data exfiltration, based on user, device, location, or app context. This capability ensures that access to sensitive data within sanctioned cloud apps is governed by granular, adaptive policies.
- ✗
Classify sensitive data across cloud apps
Why it's wrong here
Classifying sensitive data across cloud applications is a primary function of Microsoft Purview Information Protection, which discovers, labels, and protects sensitive information based on content and context. While Microsoft Defender for Cloud Apps (MDCA) can leverage existing sensitivity labels to enforce policies and prevent data exfiltration, it does not perform the initial data classification or labeling process itself. MDCA acts on the classification provided by Purview, rather than being the classification engine.
- ✓
Discover shadow IT cloud apps
Why this is correct
Discovering shadow IT cloud applications is a fundamental capability of Microsoft Defender for Cloud Apps (MDCA). By integrating with an organization's firewalls and proxy servers, MDCA ingests traffic logs to identify all cloud services accessed by users. It then assesses the risk level of these discovered applications, providing visibility into unsanctioned app usage and enabling organizations to manage the associated security and compliance risks.
Go deeper
Related to this question
Learn chapter
Session and Access Policies in Defender for Cloud Apps
Key term
Proxy
A proxy is an intermediary server that sits between a client and a destination server, forwarding requests and responses while providing security, privacy, and control.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.