Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium

A company is concerned about unmanaged and unsanctioned cloud applications (shadow IT) being used by employees, potentially leading to data exfiltration or non-compliance. They need a solution to discover these apps, assess their risk, and enforce policies. Which Microsoft security solution addresses this specific concern?

  1. AMicrosoft Defender for Cloud Apps
  2. BAzure Security Center
  3. CAzure AD Identity Protection
  4. DMicrosoft Intune
Show answer & explanation

Correct answer: A. Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security or MCAS) is a Cloud Access Security Broker (CASB) that provides visibility, control, and protection for cloud applications. It helps discover shadow IT, assess risk, and enforce policies.

Why the other options are wrong

  • B. Azure Security Center (now part of Microsoft Defender for Cloud) focuses on security posture management and threat protection for Azure resources.
  • C. Azure AD Identity Protection manages identity risks within Azure Active Directory.
  • D. Microsoft Intune manages and secures endpoints and mobile devices, not cloud application usage.

Microsoft Defender for Cloud Apps (CASB)

A Cloud Access Security Broker (CASB) that provides visibility, data control, and threat protection for cloud applications, including shadow IT discovery.

  • Identifies and assesses unsanctioned cloud apps (shadow IT)
  • Provides granular control over cloud app usage
  • Helps enforce data loss prevention (DLP) policies in the cloud

Memory trick: Defender for Apps chases shadow IT.

More Describe the capabilities of Microsoft Security solutions questions