SC-300 - Plan and Implement Workload Identities - Section 3.5

Manage and monitor app access using Microsoft Defender for Cloud Apps discovery and connected apps.

Use Microsoft Defender for Cloud Apps cloud discovery and the Cloud app catalog to identify shadow IT and assess app risk. Connect sanctioned apps and apply OAuth app policies and app governance controls to detect and restrict excessive or anomalous OAuth permissions.

cloud discoveryconnected appsOAuth app policiesCloud app catalogapp governance

Practice question for this objective

Free samplePlan and Implement Workload Identitieshard

A Conditional Access policy must place a SaaS application under Microsoft Defender for Cloud Apps so that session policies can monitor and control activity in real time. After selecting the target app and users, which session control inside the Conditional Access policy actually routes the user's session through the Defender for Cloud Apps reverse proxy?

  • AThe Sign-in frequency session control set to a short interval so the session is re-evaluated often enough for Defender for Cloud Apps to take over
  • BThe Persistent browser session control set to never persistent so each new browser session is redirected into the Defender for Cloud Apps proxy
  • CThe Use Conditional Access App Control session control, configured to use custom policy, which redirects the session to Defender for Cloud Apps Correct
  • DThe Customise continuous access evaluation session control, which streams session events to Defender for Cloud Apps for real-time policy matching
The Use Conditional Access App Control session control redirects a session to the Defender for Cloud Apps reverse proxy so session policies can apply. Conditional Access app control depends on the Use Conditional Access App Control session control, which redirects the targeted session to the Defender for Cloud Apps reverse proxy; only then can session policies inspect and control in-session activity, which sign-in frequency, persistent browser, and continuous access evaluation cannot do.

Why A is wrong: Sign-in frequency only forces periodic reauthentication; it never hands the session to the Defender for Cloud Apps proxy and so cannot enable session policies.

Why B is wrong: Persistent browser session only governs whether the sign-in stays signed in across browser restarts and has no role in routing traffic through the proxy.

Why C is correct: The Use Conditional Access App Control session control is what redirects the session to the Defender for Cloud Apps reverse proxy, where the configured session policies are then evaluated.

Why D is wrong: Continuous access evaluation handles near real-time token revocation between Microsoft services and does not proxy or hand the session to Defender for Cloud Apps.

See more SC-300 practice questions, answers explained.

More in this domain

Back to all Plan and Implement Workload Identities objectives, or the SC-300 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.