Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy
A security engineer is configuring Microsoft Defender for Cloud Apps (MDCAS) to gain visibility and control over SaaS applications used by the organization. The engineer wants to ensure that unapproved cloud applications (shadow IT) are identified and assessed for risk. Which MDCAS capability is primarily designed for this purpose?
- AConditional Access App Control
- BApp connectors
- CInformation Protection
- DCloud Discovery
Show answer & explanationAnswer & explanation
Correct answer: D. Cloud Discovery
Cloud Discovery in Microsoft Defender for Cloud Apps (MDCAS) is specifically designed to identify all cloud applications being used by an organization (including shadow IT) and assess their risk levels based on various factors.
Why the other options are wrong
- A. Conditional Access App Control provides real-time monitoring and control over access to sanctioned cloud apps, but it doesn't discover shadow IT.
- B. App connectors are used to integrate MDCAS with sanctioned cloud apps for deeper visibility and control, not for discovering unknown apps.
- C. Information Protection focuses on classifying and protecting sensitive data within approved apps, not discovering new applications.
Cloud Discovery (MDCAS)
A feature of Microsoft Defender for Cloud Apps that identifies all cloud applications used in an organization, assesses their risk, and helps manage 'shadow IT'.
- Analyzes traffic logs from network devices.
- Provides a risk score for each discovered app.
- Helps gain visibility into unsanctioned cloud app usage.
Memory trick: To discover hidden clouds, you need a good cloud discovery radar.