SC-100 - Design Security Solutions for Applications and Data - Section 4.1

Evaluate solutions for securing Microsoft 365 productivity and collaboration workloads.

Evaluate security controls for Microsoft 365 productivity and collaboration workloads by combining Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Intune with Microsoft Purview data protection. Use Microsoft Secure Score to track improvement and weigh Microsoft Copilot for Microsoft 365 data security when AI features are in scope.

Microsoft Defender for Office 365Microsoft Defender for Cloud AppsMicrosoft IntuneMicrosoft PurviewMicrosoft Secure ScoreMicrosoft Copilot for Microsoft 365 data security

Practice question for this objective

Free sampleDesign Security Solutions for Applications and Datamedium

A retailer is concerned that employees connect unsanctioned cloud storage and productivity apps to corporate data, and that risky OAuth applications are being granted broad permissions to Microsoft 365. The design must discover the cloud apps in use, score their risk, and let the security team revoke risky third-party app consents. Which capability should the architect choose to meet this shadow IT and app-governance requirement?

  • AUse Microsoft Entra Conditional Access with a require-compliant-device grant so that only managed devices can reach Microsoft 365 and unsanctioned apps cannot obtain corporate data.
  • BConfigure Microsoft Defender for Endpoint attack surface reduction rules so that unapproved applications cannot launch or persist on managed corporate endpoints across the estate.
  • CDeploy Microsoft Defender for Cloud Apps to discover used cloud apps, assign a risk score from its catalogue, and govern or revoke risky OAuth application grants made to Microsoft 365. Correct
  • DApply Microsoft Purview insider risk management policies to flag users who move data to personal services so that analysts can investigate exfiltration to unsanctioned destinations.
Cloud app discovery, risk scoring, and OAuth consent governance for Microsoft 365 are delivered by Microsoft Defender for Cloud Apps. Defender for Cloud Apps acts as a cloud access security broker that analyses traffic logs to reveal which cloud apps are being used, scores each app against a maintained risk catalogue, and provides visibility into and control over the third-party OAuth applications that have been granted access to Microsoft 365. This combination of discovery, scoring, and consent revocation is exactly what shadow IT and app governance demands, which device-centric or endpoint-centric controls cannot supply.

Why A is wrong: Conditional Access can gate access by device state and is tempting because it limits where data flows, but it does not discover the cloud apps in use, score their risk, or revoke OAuth consents, so it leaves the shadow IT and third-party app governance unaddressed.

Why B is wrong: Defender for Endpoint attack surface reduction governs what runs on a device and feels related to controlling apps, but it operates at the endpoint rather than discovering cloud SaaS usage or revoking OAuth grants in Microsoft 365, so it solves a different layer of the problem.

Why C is correct: Defender for Cloud Apps is the cloud access security broker that ingests traffic to discover apps, rates each against its risk catalogue, and inventories and revokes risky OAuth app consents, which maps directly to the discovery, scoring, and remediation the requirement names.

Why D is wrong: Insider risk management correlates user activity into risk signals and is plausible because it watches data movement, but it is built to investigate risky people rather than to inventory and score cloud apps or revoke app consents, so it does not deliver the app-governance outcome required.

See more SC-100 practice questions, answers explained.

More in this domain

Back to all Design Security Solutions for Applications and Data objectives, or the SC-100 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.