Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy

An organization is deploying Microsoft Defender for Cloud Apps (MDCAS) and needs to gain visibility into the cloud applications being used by employees, including unsanctioned 'Shadow IT' applications. They want to identify the risk level of these applications and determine which users are accessing them. Which MDCAS feature is specifically designed to discover, analyze, and report on all cloud applications accessed in the environment?

  1. AData Loss Prevention (DLP)
  2. BCloud Discovery
  3. CApp Connectors
  4. DConditional Access App Control
Show answer & explanation

Correct answer: B. Cloud Discovery

Cloud Discovery in Microsoft Defender for Cloud Apps is specifically designed to identify all cloud applications being used in an organization, assess their risk, and report on usage patterns, including 'Shadow IT'.

Why the other options are wrong

  • A. DLP focuses on protecting sensitive data, not on discovering cloud applications.
  • C. App Connectors integrate sanctioned apps with MDCAS for deeper visibility and control, but they don't discover unsanctioned apps.
  • D. Conditional Access App Control provides real-time session control for sanctioned apps, it doesn't discover new apps.

MDCAS Cloud Discovery

Cloud Discovery in Microsoft Defender for Cloud Apps identifies all cloud applications in use across an organization, assesses their risk, and helps manage 'Shadow IT'.

  • Uses traffic logs from firewalls/proxies.
  • Identifies sanctioned and unsanctioned apps.
  • Provides risk assessment and usage insights.

Memory trick: To 'discover' all the apps, you need 'Cloud Discovery', like a radar for your cloud environment.

More Mitigate threats using Microsoft Defender XDR questions