SC-100 · Question #96
Drag and Drop Question You have a Microsoft 365 subscription You need to recommend a security solution to monitor the following activities: - User accounts that were potentially compromised - Users…
The correct answer is Azure Active Directory (Azure AD) Identity Protection; Microsoft Defender for Cloud Apps. This question assesses the candidate's understanding of key Microsoft 365 security services for detecting identity compromises and suspicious cloud application activities.
Question
Exhibits
Answer Area
Drag items
Correct arrangement
- Azure Active Directory (Azure AD) Identity Protection
- Microsoft Defender for Cloud Apps
Explanation
This question assesses the candidate's understanding of key Microsoft 365 security services for detecting identity compromises and suspicious cloud application activities.
Approach. For the activity 'User accounts that were potentially compromised', the correct component is 'Azure Active Directory (Azure AD) Identity Protection'. This service is specifically designed to detect, investigate, and remediate identity-based risks, including suspicious sign-ins, leaked credentials, and other indicators of compromise related to user accounts in Azure AD. For the activity 'Users performing bulk file downloads from Microsoft SharePoint Online', the correct component is 'Microsoft Defender for Cloud Apps'. This is a Cloud Access Security Broker (CASB) solution that provides deep visibility into cloud applications, identifies and combats cyberthreats, and helps protect sensitive information. Detecting anomalous activities like bulk file downloads from SharePoint Online is a core capability of Defender for Cloud Apps, which monitors user behavior and data movement across connected cloud services.
Common mistakes.
- common_mistake. Using 'A data loss prevention (DLP) policy' for bulk file downloads from SharePoint Online is incorrect because while DLP aims to prevent data exfiltration, Microsoft Defender for Cloud Apps (a CASB) is the primary service for monitoring and detecting anomalous activity patterns like bulk downloads across cloud applications. DLP policies are more focused on content inspection and enforcement to prevent specific sensitive data from leaving, rather than the initial behavioral monitoring for large-scale activity. 'Azure Active Directory (Azure AD) Conditional Access' is incorrect for detecting compromised accounts because it acts as an enforcement engine, leveraging risk signals (often from Identity Protection) to apply policies, rather than being the primary detection mechanism itself. 'Microsoft Defender for Cloud' is incorrect for both scenarios as it primarily focuses on cloud security posture management and workload protection for Azure, AWS, and GCP infrastructure, not Microsoft 365 user identity compromise or application-level activity monitoring.
Concept tested. This question tests knowledge of Microsoft 365 security services, specifically Azure AD Identity Protection for identity-based risk detection and Microsoft Defender for Cloud Apps (CASB) for cloud application security, anomaly detection, and data governance within cloud applications like SharePoint Online.
Reference. null
Topics
Community Discussion
No community discussion yet for this question.

