Microsoft Security Operations Analyst Associate SC-200 Practice Question
While reviewing the OAuth apps page in Microsoft Defender for Cloud Apps, you find a third-party application that has a high risk score and already has access tokens for several users. You must immediately block any further user consent to this app and invalidate the access tokens that were already issued. Which governance action in Defender for Cloud Apps should you apply to the app to meet these requirements?
Mark the application as unsanctioned in Cloud Discovery
Quarantine every user that granted consent to the application
Apply the ban governance action to the application
Create a Conditional Access policy that requires multifactor authentication for the application
Applying the ban governance action to an OAuth application in Microsoft Defender for Cloud Apps performs two tasks required in this scenario. First, it revokes the existing OAuth refresh tokens that users have previously granted, so the app can no longer access Microsoft 365 data with those tokens. Second, it prevents any additional users in the tenant from granting the application consent in the future. Marking the app as unsanctioned only helps with Shadow IT discovery traffic and does not touch OAuth tokens or consent. Quarantining users is not an available governance action for OAuth apps, and Conditional Access cannot retroactively revoke existing tokens or by itself stop other users from consenting. Therefore, banning the app is the correct remediation step.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an OAuth app in Microsoft Defender for Cloud Apps?
Open an interactive chat with Bash
What happens when an app is banned in Microsoft Defender for Cloud Apps?
Open an interactive chat with Bash
How does marking an app as unsanctioned differ from banning an app in MCAS?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .