Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
An organization is deploying Microsoft Defender for Cloud Apps (MDCAS) and needs to gain visibility into all cloud applications used by their employees, including unsanctioned 'shadow IT' applications. They want to identify the risk level of these applications and control access where necessary. Which MDCAS feature is specifically designed to discover and assess these applications?
- ADLP Policies
- BActivity Policies
- CSession Policies
- DCloud Discovery
Show answer & explanationAnswer & explanation
Correct answer: D. Cloud Discovery
Cloud Discovery is a core feature of Microsoft Defender for Cloud Apps that identifies all cloud applications being accessed by users in your organization by analyzing traffic logs from firewalls and proxy servers. It then assesses their risk levels, providing visibility into shadow IT.
Why the other options are wrong
- A. DLP Policies focus on preventing sensitive data from leaving sanctioned cloud apps, not on discovering new applications.
- B. Activity Policies are used to monitor and enforce actions on specific activities *within* sanctioned cloud apps, not to discover new ones.
- C. Session Policies are used to control user sessions *within* specific cloud apps, such as blocking downloads or enforcing 'view only' mode, after the app is known.
MDCAS Cloud Discovery
Cloud Discovery in Microsoft Defender for Cloud Apps (MDCAS) identifies and analyzes all cloud applications accessed by users in an organization, providing a risk assessment and enabling the detection of 'shadow IT'.
- Analyzes traffic logs from firewalls and proxy servers.
- Identifies unsanctioned cloud apps (shadow IT).
- Provides a risk score and governance actions for discovered apps.
Memory trick: Cloud Discovery is your 'X-ray vision' for all the apps hiding in your network.