nerdexam
Microsoft

SC-100 · Question #302

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets…

The correct answer is A. Yes. The proposed solution does meet the stated goals, as Microsoft Defender XDR together with Intune-enrolled devices provides the integrated controls needed to govern device compliance and SaaS application access.

Design security solutions for applications and data

Question

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen. You have a Microsoft 365 subscription that uses Microsoft Defender XDR. The subscription contains 500 devices that are enrolled in Microsoft Intune. The subscription contains 500 users that connect to external software as a service (SaaS) apps by using the devices. You need to implement a solution that meets the following requirements:

  • Allows user access to SaaS apps that Microsoft has identified as low

risk

  • Blocks user access to SaaS apps that Microsoft has identified as high

risk Solution: You configure app protection policies in Intune, and you create a Conditional Access policy. Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(17 responses)
  • A
    82% (14)
  • B
    18% (3)

Why each option

The proposed solution does meet the stated goals, as Microsoft Defender XDR together with Intune-enrolled devices provides the integrated controls needed to govern device compliance and SaaS application access.

AYesCorrect

Microsoft Defender XDR integrates with Microsoft Intune to enforce device compliance signals as conditions for accessing external SaaS applications. Intune manages device enrollment and compliance state, while Defender XDR correlates threat signals and can restrict access for non-compliant or compromised devices, covering both the device management and SaaS app access control requirements described in the scenario.

BNo

The solution does satisfy the requirements because the combination of Microsoft Defender XDR and Intune provides the necessary device compliance enforcement and conditional access capabilities for the 500-device, 500-user SaaS environment described.

Concept tested: Microsoft Defender XDR and Intune integration for SaaS app access control

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-365-defender

Topics

#Conditional Access#SaaS App Security#Intune App Protection#Microsoft Defender for Cloud Apps

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice