Microsoft SC-300 Defender for Cloud Apps Discovery and Access Control Practice Test
Topic 12 covers defender for cloud apps discovery and access control for the Microsoft Certified: Identity and Access Administrator Associate certification. These original practice questions apply the verified SC-300 objectives to practical decisions and troubleshooting. Select one answer unless a fixed number is requested. For broader preparation, visit the SC-300 Exam Dumps page. Each option includes an explanation of the relevant behavior and scenario constraints.
Question 1
Current evidence from firewall or proxy data being used for Cloud Discovery shows that this requirement is not yet met: the appropriate discovery data source for unmanaged SaaS visibility. No new standing administrator privilege may be introduced. Which action best satisfies the requirement?
Correct Answer: B
Correct Answer
Answer B is correct because This action directly provides the appropriate discovery data source for unmanaged SaaS visibility. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is diagnosis of limited web experience from resource policy. The scenario instead requires the appropriate discovery data source for unmanaged SaaS visibility, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is validation of connector account authority and prerequisites. The scenario instead requires the appropriate discovery data source for unmanaged SaaS visibility, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is investigation of OAuth application permissions and activity. The scenario instead requires the appropriate discovery data source for unmanaged SaaS visibility, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is diagnosis of session not redirected to control service. The scenario instead requires the appropriate discovery data source for unmanaged SaaS visibility, so this option would solve an adjacent identity problem rather than the documented gap.
Question 2
Before expanding a Defender for Cloud Apps deployment, the administrator must satisfy this condition: correct interpretation of discovered usage versus sanctioned authorization. General network connectivity outside the identity path is already verified. Which action best satisfies the requirement?
Correct Answer: B
Correct Answer
Answer B is correct because This action directly provides correct interpretation of discovered usage versus sanctioned authorization. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is a clear distinction between resource-enforced restriction and session proxy. The scenario instead requires correct interpretation of discovered usage versus sanctioned authorization, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is creation of policy for risky OAuth application behavior. The scenario instead requires correct interpretation of discovered usage versus sanctioned authorization, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is diagnosis of connector health versus user sign-in failure. The scenario instead requires correct interpretation of discovered usage versus sanctioned authorization, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is creation of access policy for blocking entry condition. The scenario instead requires correct interpretation of discovered usage versus sanctioned authorization, so this option would solve an adjacent identity problem rather than the documented gap.
Question 3
The administrator is preparing an unsanctioned application being evaluated in the Cloud app catalog for production. The required condition is: prioritization of application risk using catalog evidence. Resource permissions outside the identity control are already correct. Which action best satisfies the requirement?
Correct Answer: C
Correct Answer
Answer C is correct because This action directly provides prioritization of application risk using catalog evidence. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is assessment of activity visibility after connection. The scenario instead requires prioritization of application risk using catalog evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is revocation of grant with verified impact on integrations. The scenario instead requires prioritization of application risk using catalog evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is creation of session policy for in-session download restriction. The scenario instead requires prioritization of application risk using catalog evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is route targeted session through Conditional Access app control. The scenario instead requires prioritization of application risk using catalog evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Question 4
A production issue involving firewall or proxy data being used for Cloud Discovery has been narrowed to this requirement: diagnosis of missing discovery data from source configuration. The administrator must verify the effective result from Microsoft Entra evidence. Which action best satisfies the requirement?
Correct Answer: B
Correct Answer
Answer B is correct because This action directly provides diagnosis of missing discovery data from source configuration. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is the appropriate application-enforced restriction for supported resource. The scenario instead requires diagnosis of missing discovery data from source configuration, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is a clear distinction between OAuth governance and interactive session control. The scenario instead requires diagnosis of missing discovery data from source configuration, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is application of file inspection constraint to supported content. The scenario instead requires diagnosis of missing discovery data from source configuration, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is the appropriate monitor versus block for rollout objective. The scenario instead requires diagnosis of missing discovery data from source configuration, so this option would solve an adjacent identity problem rather than the documented gap.
Question 5
The security review of a Defender for Cloud Apps deployment focuses on one acceptance criterion: the appropriate connector for supported application and permissions. The organization requires a supported Microsoft-managed control. Which action best satisfies the requirement?
Correct Answer: D
Correct Answer
Answer D is correct because This action directly provides the appropriate connector for supported application and permissions. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is route unsupported scenario to appropriate alternative control. The scenario instead requires the appropriate connector for supported application and permissions, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is resolution of competing policies using session evidence. The scenario instead requires the appropriate connector for supported application and permissions, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is assessment of catalog risk factors against business requirement. The scenario instead requires the appropriate connector for supported application and permissions, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is validation of supported application and client prerequisites. The scenario instead requires the appropriate connector for supported application and permissions, so this option would solve an adjacent identity problem rather than the documented gap.
Question 6
The team is validating a Defender for Cloud Apps deployment. The decisive requirement is: validation of connector account authority and prerequisites. The current population and assignment scope must be preserved. Choose TWO actions that together implement and verify the requirement.
Correct Answers: B, F
Correct Answers
Answer B is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.
Answer F is correct because This action directly provides validation of connector account authority and prerequisites at the correct Microsoft Entra control boundary.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is diagnosis of session not redirected to control service. It does not implement or verify validation of connector account authority and prerequisites in this scenario.
Answer C is incorrect because This action is appropriate when the requirement is the required setting for sanctioned status without assuming technical enforcement. It does not implement or verify validation of connector account authority and prerequisites in this scenario.
Answer D is incorrect because This action is appropriate when the requirement is investigation of OAuth application permissions and activity. It does not implement or verify validation of connector account authority and prerequisites in this scenario.
Answer E is incorrect because This action is appropriate when the requirement is diagnosis of limited web experience from resource policy. It does not implement or verify validation of connector account authority and prerequisites in this scenario.
Question 7
Operations staff investigating a Defender for Cloud Apps deployment have isolated the issue to: diagnosis of connector health versus user sign-in failure. Existing working access outside the stated scope must remain unchanged. Which action best satisfies the requirement?
Correct Answer: E
Correct Answer
Answer E is correct because This action directly provides diagnosis of connector health versus user sign-in failure. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is creation of access policy for blocking entry condition. The scenario instead requires diagnosis of connector health versus user sign-in failure, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is evaluation of custom application classification in discovery. The scenario instead requires diagnosis of connector health versus user sign-in failure, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is creation of policy for risky OAuth application behavior. The scenario instead requires diagnosis of connector health versus user sign-in failure, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is a clear distinction between resource-enforced restriction and session proxy. The scenario instead requires diagnosis of connector health versus user sign-in failure, so this option would solve an adjacent identity problem rather than the documented gap.
Question 8
The administrator must correct a Defender for Cloud Apps deployment without changing adjacent controls. The target condition is: assessment of activity visibility after connection. The change will be piloted before broader enforcement. Which action best satisfies the requirement?
Correct Answer: A
Correct Answer
Answer A is correct because This action directly provides assessment of activity visibility after connection. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer B is incorrect because This action is appropriate when the requirement is reconciliation of catalog information with current app evidence. The scenario instead requires assessment of activity visibility after connection, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is route targeted session through Conditional Access app control. The scenario instead requires assessment of activity visibility after connection, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is creation of session policy for in-session download restriction. The scenario instead requires assessment of activity visibility after connection, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is revocation of grant with verified impact on integrations. The scenario instead requires assessment of activity visibility after connection, so this option would solve an adjacent identity problem rather than the documented gap.
Question 9
An audit of a supported application enforcing limited web access identifies this control gap: the appropriate application-enforced restriction for supported resource. The tenant has the licensing required for the named capability. Which action best satisfies the requirement?
Correct Answer: C
Correct Answer
Answer C is correct because This action directly provides the appropriate application-enforced restriction for supported resource. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is a clear distinction between OAuth governance and interactive session control. The scenario instead requires the appropriate application-enforced restriction for supported resource, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is the appropriate discovery data source for unmanaged SaaS visibility. The scenario instead requires the appropriate application-enforced restriction for supported resource, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is the appropriate monitor versus block for rollout objective. The scenario instead requires the appropriate application-enforced restriction for supported resource, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is application of file inspection constraint to supported content. The scenario instead requires the appropriate application-enforced restriction for supported resource, so this option would solve an adjacent identity problem rather than the documented gap.
Question 10
The documented success criterion for a Defender for Cloud Apps deployment is: route unsupported scenario to appropriate alternative control. The correction must address the named control boundary rather than reset unrelated tenant settings. Which action best satisfies the requirement?
Correct Answer: A
Correct Answer
Answer A is correct because This action directly provides route unsupported scenario to appropriate alternative control. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer B is incorrect because This action is appropriate when the requirement is validation of supported application and client prerequisites. The scenario instead requires route unsupported scenario to appropriate alternative control, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is correct interpretation of discovered usage versus sanctioned authorization. The scenario instead requires route unsupported scenario to appropriate alternative control, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is assessment of catalog risk factors against business requirement. The scenario instead requires route unsupported scenario to appropriate alternative control, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is resolution of competing policies using session evidence. The scenario instead requires route unsupported scenario to appropriate alternative control, so this option would solve an adjacent identity problem rather than the documented gap.
Question 11
The current configuration of a Defender for Cloud Apps deployment is otherwise acceptable. The unresolved requirement is: diagnosis of limited web experience from resource policy. No new standing administrator privilege may be introduced. Which action best satisfies the requirement?
Correct Answer: B
Correct Answer
Answer B is correct because This action directly provides diagnosis of limited web experience from resource policy. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is the required setting for sanctioned status without assuming technical enforcement. The scenario instead requires diagnosis of limited web experience from resource policy, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is investigation of OAuth application permissions and activity. The scenario instead requires diagnosis of limited web experience from resource policy, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is prioritization of application risk using catalog evidence. The scenario instead requires diagnosis of limited web experience from resource policy, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is diagnosis of session not redirected to control service. The scenario instead requires diagnosis of limited web experience from resource policy, so this option would solve an adjacent identity problem rather than the documented gap.
Question 12
A troubleshooting review of a cloud-app session requiring download or upload controls confirms that the next action must address: a clear distinction between resource-enforced restriction and session proxy. General network connectivity outside the identity path is already verified. Choose TWO actions that together implement and verify the requirement.
Correct Answers: A, F
Correct Answers
Answer A is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.
Answer F is correct because This action directly provides a clear distinction between resource-enforced restriction and session proxy at the correct Microsoft Entra control boundary.
Incorrect Answers
Answer B is incorrect because This action is appropriate when the requirement is creation of access policy for blocking entry condition. It does not implement or verify a clear distinction between resource-enforced restriction and session proxy in this scenario.
Answer C is incorrect because This action is appropriate when the requirement is evaluation of custom application classification in discovery. It does not implement or verify a clear distinction between resource-enforced restriction and session proxy in this scenario.
Answer D is incorrect because This action is appropriate when the requirement is creation of policy for risky OAuth application behavior. It does not implement or verify a clear distinction between resource-enforced restriction and session proxy in this scenario.
Answer E is incorrect because This action is appropriate when the requirement is diagnosis of missing discovery data from source configuration. It does not implement or verify a clear distinction between resource-enforced restriction and session proxy in this scenario.
Question 13
A staged rollout of a cloud-app session requiring download or upload controls cannot proceed until the team can demonstrate: route targeted session through Conditional Access app control. Resource permissions outside the identity control are already correct. Which action best satisfies the requirement?
Correct Answer: A
Correct Answer
Answer A is correct because This action directly provides route targeted session through Conditional Access app control. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer B is incorrect because This action is appropriate when the requirement is creation of session policy for in-session download restriction. The scenario instead requires route targeted session through Conditional Access app control, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is the appropriate connector for supported application and permissions. The scenario instead requires route targeted session through Conditional Access app control, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is reconciliation of catalog information with current app evidence. The scenario instead requires route targeted session through Conditional Access app control, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is revocation of grant with verified impact on integrations. The scenario instead requires route targeted session through Conditional Access app control, so this option would solve an adjacent identity problem rather than the documented gap.
Question 14
The team compares supported controls for a Defender for Cloud Apps deployment. The deciding condition is: the appropriate monitor versus block for rollout objective. The administrator must verify the effective result from Microsoft Entra evidence. Which action best satisfies the requirement?
Correct Answer: B
Correct Answer
Answer B is correct because This action directly provides the appropriate monitor versus block for rollout objective. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is application of file inspection constraint to supported content. The scenario instead requires the appropriate monitor versus block for rollout objective, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is the appropriate discovery data source for unmanaged SaaS visibility. The scenario instead requires the appropriate monitor versus block for rollout objective, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is a clear distinction between OAuth governance and interactive session control. The scenario instead requires the appropriate monitor versus block for rollout objective, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is validation of connector account authority and prerequisites. The scenario instead requires the appropriate monitor versus block for rollout objective, so this option would solve an adjacent identity problem rather than the documented gap.
Question 15
The identity architect is reviewing a Defender for Cloud Apps deployment. The required outcome is: validation of supported application and client prerequisites. The organization requires a supported Microsoft-managed control. Which action best satisfies the requirement?
Correct Answer: A
Correct Answer
Answer A is correct because This action directly provides validation of supported application and client prerequisites. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer B is incorrect because This action is appropriate when the requirement is diagnosis of connector health versus user sign-in failure. The scenario instead requires validation of supported application and client prerequisites, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is resolution of competing policies using session evidence. The scenario instead requires validation of supported application and client prerequisites, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is correct interpretation of discovered usage versus sanctioned authorization. The scenario instead requires validation of supported application and client prerequisites, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is assessment of catalog risk factors against business requirement. The scenario instead requires validation of supported application and client prerequisites, so this option would solve an adjacent identity problem rather than the documented gap.
Question 16
The change owner has limited the remediation for a cloud-app session requiring download or upload controls to this outcome: diagnosis of session not redirected to control service. The current population and assignment scope must be preserved. Which action best satisfies the requirement?
Correct Answer: C
Correct Answer
Answer C is correct because This action directly provides diagnosis of session not redirected to control service. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is investigation of OAuth application permissions and activity. The scenario instead requires diagnosis of session not redirected to control service, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is the required setting for sanctioned status without assuming technical enforcement. The scenario instead requires diagnosis of session not redirected to control service, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is assessment of activity visibility after connection. The scenario instead requires diagnosis of session not redirected to control service, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is prioritization of application risk using catalog evidence. The scenario instead requires diagnosis of session not redirected to control service, so this option would solve an adjacent identity problem rather than the documented gap.
Question 17
A change request for a cloud app that must be blocked before a session starts will be accepted only when the following is true: creation of access policy for blocking entry condition. Existing working access outside the stated scope must remain unchanged. Which action best satisfies the requirement?
Correct Answer: A
Correct Answer
Answer A is correct because This action directly provides creation of access policy for blocking entry condition. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer B is incorrect because This action is appropriate when the requirement is the appropriate application-enforced restriction for supported resource. The scenario instead requires creation of access policy for blocking entry condition, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is creation of policy for risky OAuth application behavior. The scenario instead requires creation of access policy for blocking entry condition, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is evaluation of custom application classification in discovery. The scenario instead requires creation of access policy for blocking entry condition, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is diagnosis of missing discovery data from source configuration. The scenario instead requires creation of access policy for blocking entry condition, so this option would solve an adjacent identity problem rather than the documented gap.
Question 18
The implementation of a cloud-app session requiring download or upload controls is complete except for this requirement: creation of session policy for in-session download restriction. The change will be piloted before broader enforcement. Choose TWO actions that together implement and verify the requirement.
Correct Answers: D, E
Correct Answers
Answer D is correct because This action directly provides creation of session policy for in-session download restriction at the correct Microsoft Entra control boundary.
Answer E is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is the appropriate connector for supported application and permissions. It does not implement or verify creation of session policy for in-session download restriction in this scenario.
Answer B is incorrect because This action is appropriate when the requirement is route unsupported scenario to appropriate alternative control. It does not implement or verify creation of session policy for in-session download restriction in this scenario.
Answer C is incorrect because This action is appropriate when the requirement is revocation of grant with verified impact on integrations. It does not implement or verify creation of session policy for in-session download restriction in this scenario.
Answer F is incorrect because This action is appropriate when the requirement is reconciliation of catalog information with current app evidence. It does not implement or verify creation of session policy for in-session download restriction in this scenario.
Question 19
The support team has ruled out unrelated causes in a Defender for Cloud Apps deployment. The remaining issue is: application of file inspection constraint to supported content. The tenant has the licensing required for the named capability. Which action best satisfies the requirement?
Correct Answer: E
Correct Answer
Answer E is correct because This action directly provides application of file inspection constraint to supported content. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is a clear distinction between OAuth governance and interactive session control. The scenario instead requires application of file inspection constraint to supported content, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is diagnosis of limited web experience from resource policy. The scenario instead requires application of file inspection constraint to supported content, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is the appropriate discovery data source for unmanaged SaaS visibility. The scenario instead requires application of file inspection constraint to supported content, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is validation of connector account authority and prerequisites. The scenario instead requires application of file inspection constraint to supported content, so this option would solve an adjacent identity problem rather than the documented gap.
Question 20
A readiness check of a cloud-app session requiring download or upload controls leaves one unresolved condition: resolution of competing policies using session evidence. The correction must address the named control boundary rather than reset unrelated tenant settings. Which action best satisfies the requirement?
Correct Answer: A
Correct Answer
Answer A is correct because This action directly provides resolution of competing policies using session evidence. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer B is incorrect because This action is appropriate when the requirement is a clear distinction between resource-enforced restriction and session proxy. The scenario instead requires resolution of competing policies using session evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is correct interpretation of discovered usage versus sanctioned authorization. The scenario instead requires resolution of competing policies using session evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is assessment of catalog risk factors against business requirement. The scenario instead requires resolution of competing policies using session evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is diagnosis of connector health versus user sign-in failure. The scenario instead requires resolution of competing policies using session evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Question 21
Testing of a consented OAuth application with broad permissions is successful except for this condition: investigation of OAuth application permissions and activity. No new standing administrator privilege may be introduced. Which action best satisfies the requirement?
Correct Answer: C
Correct Answer
Answer C is correct because This action directly provides investigation of OAuth application permissions and activity. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is assessment of activity visibility after connection. The scenario instead requires investigation of OAuth application permissions and activity, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is the required setting for sanctioned status without assuming technical enforcement. The scenario instead requires investigation of OAuth application permissions and activity, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is route targeted session through Conditional Access app control. The scenario instead requires investigation of OAuth application permissions and activity, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is prioritization of application risk using catalog evidence. The scenario instead requires investigation of OAuth application permissions and activity, so this option would solve an adjacent identity problem rather than the documented gap.
Question 22
The organization wants the least-disruptive correction to a consented OAuth application with broad permissions. It must provide: creation of policy for risky OAuth application behavior. General network connectivity outside the identity path is already verified. Which action best satisfies the requirement?
Correct Answer: E
Correct Answer
Answer E is correct because This option directly tests create policy for risky oauth application behavior at the control boundary named in the scenario. It addresses that specific stage or distinction rather than collapsing it into a neighboring workflow step.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is the appropriate application-enforced restriction for supported resource. The scenario instead requires creation of policy for risky OAuth application behavior, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is evaluation of custom application classification in discovery. The scenario instead requires creation of policy for risky OAuth application behavior, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is diagnosis of missing discovery data from source configuration. The scenario instead requires creation of policy for risky OAuth application behavior, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is the appropriate monitor versus block for rollout objective. The scenario instead requires creation of policy for risky OAuth application behavior, so this option would solve an adjacent identity problem rather than the documented gap.
Question 23
A design review of a Defender for Cloud Apps deployment identifies one remaining requirement: revocation of grant with verified impact on integrations. Resource permissions outside the identity control are already correct. Which action best satisfies the requirement?
Correct Answer: D
Correct Answer
Answer D is correct because This action directly provides revocation of grant with verified impact on integrations. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is reconciliation of catalog information with current app evidence. The scenario instead requires revocation of grant with verified impact on integrations, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is validation of supported application and client prerequisites. The scenario instead requires revocation of grant with verified impact on integrations, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is the appropriate connector for supported application and permissions. The scenario instead requires revocation of grant with verified impact on integrations, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is route unsupported scenario to appropriate alternative control. The scenario instead requires revocation of grant with verified impact on integrations, so this option would solve an adjacent identity problem rather than the documented gap.
Question 24
Current evidence from a cloud-app session requiring download or upload controls shows that this requirement is not yet met: a clear distinction between OAuth governance and interactive session control. The administrator must verify the effective result from Microsoft Entra evidence. Choose TWO actions that together implement and verify the requirement.
Correct Answers: D, F
Correct Answers
Answer D is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.
Answer F is correct because This action directly provides a clear distinction between OAuth governance and interactive session control at the correct Microsoft Entra control boundary.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is validation of connector account authority and prerequisites. It does not implement or verify a clear distinction between OAuth governance and interactive session control in this scenario.
Answer B is incorrect because This action is appropriate when the requirement is diagnosis of limited web experience from resource policy. It does not implement or verify a clear distinction between OAuth governance and interactive session control in this scenario.
Answer C is incorrect because This action is appropriate when the requirement is diagnosis of session not redirected to control service. It does not implement or verify a clear distinction between OAuth governance and interactive session control in this scenario.
Answer E is incorrect because This action is appropriate when the requirement is the appropriate discovery data source for unmanaged SaaS visibility. It does not implement or verify a clear distinction between OAuth governance and interactive session control in this scenario.
Question 25
Before expanding an unsanctioned application being evaluated in the Cloud app catalog, the administrator must satisfy this condition: assessment of catalog risk factors against business requirement. The organization requires a supported Microsoft-managed control. Which action best satisfies the requirement?
Correct Answer: D
Correct Answer
Answer D is correct because This action directly provides assessment of catalog risk factors against business requirement. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is a clear distinction between resource-enforced restriction and session proxy. The scenario instead requires assessment of catalog risk factors against business requirement, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is diagnosis of connector health versus user sign-in failure. The scenario instead requires assessment of catalog risk factors against business requirement, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is correct interpretation of discovered usage versus sanctioned authorization. The scenario instead requires assessment of catalog risk factors against business requirement, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is creation of access policy for blocking entry condition. The scenario instead requires assessment of catalog risk factors against business requirement, so this option would solve an adjacent identity problem rather than the documented gap.
Question 26
The administrator is preparing a Defender for Cloud Apps deployment for production. The required condition is: the required setting for sanctioned status without assuming technical enforcement. The current population and assignment scope must be preserved. Which action best satisfies the requirement?
Correct Answer: A
Correct Answer
Answer A is correct because This action directly provides the required setting for sanctioned status without assuming technical enforcement. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer B is incorrect because This action is appropriate when the requirement is assessment of activity visibility after connection. The scenario instead requires the required setting for sanctioned status without assuming technical enforcement, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is creation of session policy for in-session download restriction. The scenario instead requires the required setting for sanctioned status without assuming technical enforcement, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is route targeted session through Conditional Access app control. The scenario instead requires the required setting for sanctioned status without assuming technical enforcement, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is prioritization of application risk using catalog evidence. The scenario instead requires the required setting for sanctioned status without assuming technical enforcement, so this option would solve an adjacent identity problem rather than the documented gap.
Question 27
A production issue involving firewall or proxy data being used for Cloud Discovery has been narrowed to this requirement: evaluation of custom application classification in discovery. Existing working access outside the stated scope must remain unchanged. Which action best satisfies the requirement?
Correct Answer: D
Correct Answer
Answer D is correct because This action directly resolves evaluate custom application classification in discovery at the evidence or control boundary described by the scenario, rather than substituting a neighboring identity workflow.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is the appropriate monitor versus block for rollout objective. The scenario instead requires evaluation of custom application classification in discovery, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is application of file inspection constraint to supported content. The scenario instead requires evaluation of custom application classification in discovery, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is diagnosis of missing discovery data from source configuration. The scenario instead requires evaluation of custom application classification in discovery, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is the appropriate application-enforced restriction for supported resource. The scenario instead requires evaluation of custom application classification in discovery, so this option would solve an adjacent identity problem rather than the documented gap.
Question 28
The security review of an unsanctioned application being evaluated in the Cloud app catalog focuses on one acceptance criterion: reconciliation of catalog information with current app evidence. The change will be piloted before broader enforcement. Which action best satisfies the requirement?
Correct Answer: D
Correct Answer
Answer D is correct because This action directly resolves reconcile catalog information with current app evidence at the evidence or control boundary described by the scenario, rather than substituting a neighboring identity workflow.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is route unsupported scenario to appropriate alternative control. The scenario instead requires reconciliation of catalog information with current app evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is validation of supported application and client prerequisites. The scenario instead requires reconciliation of catalog information with current app evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is resolution of competing policies using session evidence. The scenario instead requires reconciliation of catalog information with current app evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is the appropriate connector for supported application and permissions. The scenario instead requires reconciliation of catalog information with current app evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Popular posts
Recent Posts
