nerdexam
Microsoft

SC-200 · Question #379

You have a Microsoft 365 E5 subscription. You need to configure Microsoft Defender XDR automatic attack disruption to use signals generated by Microsoft Defender for Cloud Apps. Which two actions…

The correct answer is A. Enable the Microsoft 365 connector. C. Turn on app governance. For Microsoft Defender XDR automatic attack disruption to leverage signals from Microsoft Defender for Cloud Apps, two actions are required. First, enabling the Microsoft 365 connector (A) integrates Cloud Apps data into Defender XDR, making its signals available to the attack…

Submitted by neha2k· Apr 18, 2026

Question

You have a Microsoft 365 E5 subscription. You need to configure Microsoft Defender XDR automatic attack disruption to use signals generated by Microsoft Defender for Cloud Apps. Which two actions should you perform for Defender for Cloud Apps in the Microsoft Defender portal? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AEnable the Microsoft 365 connector.
  • BAdd a log collector for automatic log upload.
  • CTurn on app governance.
  • DDeploy Cloud Discovery user enrichment.
  • EFrom Information protection, enable file monitoring.

How the community answered

(18 responses)
  • A
    78% (14)
  • B
    6% (1)
  • D
    11% (2)
  • E
    6% (1)

Explanation

For Microsoft Defender XDR automatic attack disruption to leverage signals from Microsoft Defender for Cloud Apps, two actions are required. First, enabling the Microsoft 365 connector (A) integrates Cloud Apps data into Defender XDR, making its signals available to the attack disruption engine. Second, turning on app governance (C) provides the governance and behavioral analytics layer within Cloud Apps that generates the high-fidelity signals - particularly around OAuth app abuse and anomalous app behavior - that attack disruption acts on. Adding a log collector (B) is for Cloud Discovery and does not feed into attack disruption signals. Cloud Discovery user enrichment (D) and file monitoring (E) are unrelated to the attack disruption signal pipeline.

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice