Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

You are a security administrator for a company that uses Microsoft Defender for Cloud Apps. The security team wants to detect and respond to risky user activities and unsanctioned cloud app usage. Which two capabilities does Defender for Cloud Apps provide? (Choose two.)

⚠ Common exam trap

The trap here is mixing capabilities from Microsoft Defender for Cloud and Defender for Endpoint into Defender for Cloud Apps, which actually focuses on cloud app discovery and user activity analytics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Anomaly detection policies to identify risky user behavior.

Defender for Cloud Apps provides Cloud Discovery to find shadow IT and unsanctioned apps, and anomaly detection policies to surface risky user behavior. These two capabilities directly match the team's goals. Endpoint EDR, just-in-time VM access, and attack path analysis belong to other Defender services and do not address cloud app discovery or user activity monitoring.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Just-in-time virtual machine access in Azure.

    Why it's wrong here

    Just-in-time VM access is a feature of Microsoft Defender for Cloud that reduces exposure by opening management ports on demand. It is not part of Defender for Cloud Apps. This scenario is about cloud app usage and user activity monitoring, so JIT VM access is unrelated and does not help detect shadow IT or risky user behavior in cloud apps.

  • ✗

    Attack path analysis for multicloud resources.

    Why it's wrong here

    Attack path analysis is a capability in Microsoft Defender for Cloud that helps identify and remediate potential attack paths across cloud resources. It is not a Defender for Cloud Apps feature. This scenario requires detecting unsanctioned apps and risky user activities, which are handled by Cloud Discovery and anomaly detection policies, not by attack path analysis.

  • ✓

    Anomaly detection policies to identify risky user behavior.

    Why this is correct

    Defender for Cloud Apps includes anomaly detection policies that use Microsoft threat intelligence and behavior analytics to identify risky activities such as impossible travel, mass downloads, or suspicious inbox rules. These policies generate alerts that security teams can investigate and respond to. This meets the requirement to detect and respond to risky user activities.

  • ✓

    Cloud Discovery to identify shadow IT and unsanctioned apps.

    Why this is correct

    Cloud Discovery analyzes traffic logs from firewalls and proxies to discover which cloud apps are in use, including unsanctioned shadow IT. It provides risk scores and allows administrators to sanction or unsanction apps. This directly addresses the need to detect unsanctioned cloud app usage, making it a correct capability in this scenario.

  • ✗

    Endpoint detection and response for Windows devices.

    Why it's wrong here

    Endpoint detection and response for Windows devices is provided by Microsoft Defender for Endpoint, not Defender for Cloud Apps. Defender for Cloud Apps focuses on cloud app visibility, data controls, and threat detection for cloud services. While it can integrate with Defender for Endpoint, it does not itself provide endpoint EDR capabilities, so this is not a correct capability for this scenario.

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.