Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security analyst is investigating an incident where a user's credentials were potentially compromised. The analyst needs to determine if the compromised credentials were used to access any cloud applications, such as Salesforce or Dropbox, and if any sensitive data was downloaded. Which Microsoft Defender XDR component is best suited to provide this specific visibility and control over cloud app usage?
- AMicrosoft Defender for Cloud Apps
- BMicrosoft Defender for Office 365
- CMicrosoft Defender for Endpoint
- DMicrosoft Defender for Identity
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps (MDCAS) provides deep visibility and control over cloud applications, enabling the security team to monitor access, detect anomalous behavior, and investigate activities like data downloads from SaaS applications.
Why the other options are wrong
- B. Defender for Office 365 protects Microsoft's own M365 services, not third-party SaaS applications like Salesforce or Dropbox.
- C. Defender for Endpoint focuses on device-level activities, not specific cloud application access or data transfer within SaaS apps.
- D. Defender for Identity monitors on-premises and hybrid identity activities, but does not provide granular visibility into SaaS app sessions or data specific to those apps.
Microsoft Defender for Cloud Apps (MDCAS)
A Cloud Access Security Broker (CASB) that provides comprehensive visibility, control, and protection for cloud applications, both sanctioned and unsanctioned.
- Monitors user activities in cloud apps.
- Detects anomalous behavior and threats.
- Enforces data loss prevention (DLP) policies for cloud apps.
Memory trick: To see inside cloud apps, you need the Defender that's 'for Cloud Apps'.