nerdexam
Microsoft

MS-102 · Question #324

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. The subscription contains users that have Windows 11 devices. You need to use the Cloud Discovery snapshot report…

The correct answer is C. Export traffic logs from firewalls and proxies. The Cloud Discovery snapshot report in Microsoft Defender for Cloud Apps is a manual upload process - it does not use agents or auto-discovery on its own. Before generating a snapshot report, you must export traffic logs from your firewalls, proxies, or other network appliances…

Submitted by renata2k· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. The subscription contains users that have Windows 11 devices. You need to use the Cloud Discovery snapshot report to analyze cloud app usage on the devices. What should you do before generating a report?

Options

  • ACreate an activity policy.
  • BDeploy the Azure Monitor Agent on the devices.
  • CExport traffic logs from firewalls and proxies.
  • DCreate an app discovery policy.

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    94% (30)

Explanation

The Cloud Discovery snapshot report in Microsoft Defender for Cloud Apps is a manual upload process - it does not use agents or auto-discovery on its own. Before generating a snapshot report, you must export traffic logs from your firewalls, proxies, or other network appliances that capture user internet traffic, then upload those logs to Defender for Cloud Apps. The portal parses the logs to identify cloud app usage. Options A and D (policies) and B (Azure Monitor Agent) are unrelated to the snapshot report workflow.

Topics

#Microsoft Defender for Cloud Apps#Cloud Discovery#Shadow IT#Log collection

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice