SC-900 Microsoft Defender for Cloud Apps 1 — Questions and Answers
Question 1: What type of security solution is Microsoft Defender for Cloud Apps primarily classified as?
- Security Information and Event Management (SIEM)
- Cloud Access Security Broker (CASB) (Correct answer)
- Extended Detection and Response (XDR)
- Security Orchestration Automated Response (SOAR)
Correct answer: Cloud Access Security Broker (CASB)
Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility, data control, and threat protection for cloud apps.
Question 2: Which feature of Microsoft Defender for Cloud Apps helps organizations discover unsanctioned cloud applications being used by employees?
- Cloud Discovery (Correct answer)
- Conditional Access App Control
- App Connectors
- Session Policies
Correct answer: Cloud Discovery
Cloud Discovery analyzes traffic logs to identify cloud apps in use across the organization, revealing Shadow IT.
Question 3: What term describes the use of unauthorized or unapproved cloud applications within an organization that Defender for Cloud Apps helps identify?
- Dark Web
- Shadow IT (Correct answer)
- Rogue Apps
- Unsecured APIs
Correct answer: Shadow IT
Shadow IT refers to cloud apps and services used by employees without IT department knowledge or approval, which Cloud Discovery helps uncover.
Question 4: Which of the following is NOT one of the four pillars of the Cloud Access Security Broker (CASB) framework that Defender for Cloud Apps provides?
- Visibility
- Compliance
- Data Security
- Network Segmentation (Correct answer)
Correct answer: Network Segmentation
The four CASB pillars are Visibility, Compliance, Data Security, and Threat Protection — Network Segmentation is not a CASB pillar.
Question 5: What does Conditional Access App Control in Microsoft Defender for Cloud Apps enable?
- Blocking all third-party cloud applications
- Real-time session monitoring and control of user activity in cloud apps (Correct answer)
- Automatic patching of cloud application vulnerabilities
- Encrypting all data stored in cloud applications
Correct answer: Real-time session monitoring and control of user activity in cloud apps
Conditional Access App Control uses reverse proxy architecture to monitor and control user sessions and access to cloud apps in real time.
Question 6: How does Microsoft Defender for Cloud Apps connect to supported third-party cloud applications to gain deeper visibility?
- Through network packet inspection
- Via App Connectors using provider APIs (Correct answer)
- By installing agents on user devices
- Through DNS sinkholing
Correct answer: Via App Connectors using provider APIs
App Connectors use APIs provided by cloud service providers to connect Defender for Cloud Apps and give visibility into activities and data within those platforms.
Question 7: Which Microsoft Defender for Cloud Apps capability allows administrators to set policies that trigger alerts when unusual user behavior is detected?
- Cloud Discovery Snapshots
- Anomaly Detection Policies (Correct answer)
- File Scan Policies
- App Risk Scoring
Correct answer: Anomaly Detection Policies
Anomaly Detection Policies use behavioral analytics and machine learning to detect unusual activities that could indicate a threat.
What type of security solution is Microsoft Defender for Cloud Apps primarily classified as?