← All SC-900 Flashcard Decks

Microsoft Defender for Cloud Apps Flashcards

7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Microsoft Defender for Cloud Apps flashcards as text
  1. How does Microsoft Defender for Cloud Apps integrate with Microsoft Sentinel?

    Answer: Defender for Cloud Apps sends alerts and data to Sentinel for centralized SIEM analysis

    Defender for Cloud Apps can stream alerts, activities, and discovery data to Microsoft Sentinel, enabling centralized investigation and correlation in the SIEM.

  2. Which Defender for Cloud Apps capability helps detect when a user account may have been compromised by analyzing impossible travel scenarios?

    Answer: Anomaly Detection — Impossible Travel

    The Impossible Travel anomaly detection policy identifies when a user logs in from two geographically distant locations within a timeframe that makes physical travel impossible, suggesting account compromise.

  3. What is the primary benefit of using Microsoft Defender for Cloud Apps 'Governance Actions'?

    Answer: Automatically remediating policy violations in connected cloud apps without manual intervention

    Governance Actions allow Defender for Cloud Apps to automatically remediate issues — such as revoking sharing permissions, quarantining files, or suspending users — when policies are triggered.

  4. Which of the following best describes the 'Session Policy' capability in Microsoft Defender for Cloud Apps?

    Answer: Real-time controls that allow monitoring and restricting specific user activities during a cloud app session

    Session Policies use Conditional Access App Control to provide real-time visibility and control over what users can do within a cloud app session, such as blocking downloads of sensitive files.

  5. In the context of Microsoft Defender for Cloud Apps, what does 'sanctioning' a cloud application mean?

    Answer: Officially approving an app for use within the organization

    Sanctioning a cloud app marks it as approved for organizational use in the Cloud App Catalog, which can also be used to configure firewall and proxy rules to allow its traffic.

  6. Which of the following is a key compliance benefit that Microsoft Defender for Cloud Apps provides?

    Answer: It shows whether cloud apps meet regulatory compliance standards such as HIPAA, PCI DSS, and ISO 27001

    The Cloud App Catalog includes compliance attributes for each app (such as HIPAA, PCI DSS, ISO 27001 certifications), enabling organizations to quickly assess if an app meets their regulatory requirements.

  7. What Microsoft 365 Defender capability does Microsoft Defender for Cloud Apps contribute to when integrated into the unified security operations platform?

    Answer: Cross-domain threat signals for extended detection and response (XDR)

    As part of the Microsoft Defender XDR suite, Defender for Cloud Apps contributes cloud app threat signals that correlate with endpoint, identity, and email signals for comprehensive cross-domain threat detection.