Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your organization uses Microsoft Defender for Cloud Apps to monitor cloud app usage. You discover that a user is accessing a sanctioned app from an unmanaged device. You need to ensure that when users access this app from unmanaged devices, they are prompted for additional authentication and their session is monitored. What should you configure?

⚠ Common exam trap

It's easy for candidates to confuse session control (which allows conditional access with monitoring) with device compliance policies (which block or allow based on device state) or Identity Protection (which focuses on risk-based sign-in detection).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a Conditional Access policy that uses the 'Require session control' grant and target 'All cloud apps' and 'Unmanaged devices' as conditions.

You need to use a Conditional Access policy with the 'Require session control' grant, targeting 'All cloud apps' and 'Unmanaged devices' as conditions. This integrates with Microsoft Defender for Cloud Apps to enforce additional authentication (via Microsoft Entra ID) and enable session monitoring, such as real-time activity logging and download blocking, for the sanctioned app when accessed from unmanaged devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable Microsoft Entra ID Identity Protection and configure a sign-in risk policy.

    Why it's wrong here

    Enabling Microsoft Entra ID Identity Protection and configuring a sign-in risk policy primarily focuses on detecting and remediating identity-based risks, such as compromised credentials or unusual sign-in patterns. While essential for overall security, this feature does not provide the granular session control or real-time monitoring capabilities specifically required to manage user interactions with cloud applications from unmanaged devices. It addresses *who* is signing in and *how risky* that sign-in is, rather than controlling *what actions* they can perform on a specific device type.

  • Create a Conditional Access policy that requires device compliance and block access for non-compliant devices.

    Why it's wrong here

    Creating a Conditional Access policy that requires device compliance and blocks access for non-compliant devices is a valid security measure, but it enforces an all-or-nothing approach. This policy would completely deny access to cloud applications from any device deemed non-compliant, which might hinder productivity if the goal is to allow access from unmanaged devices under strict monitoring and control. The intent of using Microsoft Defender for Cloud Apps in this context is typically to permit access while applying specific restrictions, not to block it outright.

  • Create a session policy in Microsoft Defender for Cloud Apps that blocks downloads for all devices.

    Why it's wrong here

    Creating a session policy in Microsoft Defender for Cloud Apps that blocks downloads for all devices is overly broad and does not align with the common requirement to differentiate between trusted and untrusted environments. Applying such a restrictive policy universally would unnecessarily impede users on managed, compliant devices, where downloads might be permitted. Effective security often requires targeting specific conditions, such as unmanaged devices, to apply more stringent controls without impacting the productivity of trusted users and devices.

  • Create a Conditional Access policy that uses the 'Require session control' grant and target 'All cloud apps' and 'Unmanaged devices' as conditions.

    Why this is correct

    Creating a Conditional Access policy that uses the 'Require session control' grant and targets 'All cloud apps' and 'Unmanaged devices' as conditions is the correct approach. This configuration seamlessly integrates Microsoft Entra Conditional Access with Microsoft Defender for Cloud Apps (MDCA), routing sessions from unmanaged devices through MDCA's reverse proxy. This allows MDCA to apply granular, real-time session controls, such as blocking downloads, restricting copy-paste, or enforcing read-only access, specifically for those less trusted sessions while still permitting access to the cloud applications.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.