Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsHard
A financial institution needs to monitor and control how sensitive data is used within sanctioned cloud applications (e.g., Microsoft 365, Salesforce) and identify unsanctioned 'shadow IT' applications. They also need to enforce data loss prevention (DLP) policies for data in these cloud apps. Which Microsoft security solution provides these capabilities?
- AMicrosoft Defender for Cloud Apps
- BMicrosoft Intune
- CMicrosoft Purview Information Protection
- DMicrosoft Defender for Endpoint
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security) functions as a Cloud Access Security Broker (CASB) offering deep visibility into cloud apps, discovering shadow IT, enforcing DLP policies, and protecting sensitive data across sanctioned and unsanctioned cloud services.
Why the other options are wrong
- B. Microsoft Intune manages devices and mobile applications, not primarily focused on cloud app oversight and DLP within those apps.
- C. Microsoft Purview Information Protection classifies and labels sensitive data, but Defender for Cloud Apps is the enforcement point for DLP within cloud applications themselves, and for discovering shadow IT.
- D. Microsoft Defender for Endpoint protects endpoint devices from threats, not cloud applications or shadow IT.
Microsoft Defender for Cloud Apps (CASB)
A Cloud Access Security Broker (CASB) that extends visibility and control over cloud applications, discovers shadow IT, and enforces data protection policies.
- Discovers and identifies all cloud apps (sanctioned/unsanctioned).
- Enforces DLP and compliance policies in cloud apps.
- Provides granular control over user activities in cloud apps.
Memory trick: Cloud Apps Defender: Catch All, Control All, Comply All.