How to Track Audited Cloud Discovery Apps in Defender for Cloud Apps?

Implement and manage Microsoft Defender for Cloud Apps
Answer Correct answer: E — Apply a custom app tag to each audited app so Cloud Discovery audit status is stored on the app and displayed in the cloud app catalog.

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. You plan to perform a security audit of all the apps detected by Cloud Discovery. You need to track which apps were audited. The solution must ensure that the list of audited apps can be displayed in the cloud app catalog. What should you do?

  1. Define each app as a critical asset.
  2. Deploy Conditional Access App Control.
  3. Enable app governance.
  4. Generate a Cloud Discovery snapshot report.
  5. Apply a custom app tag to each app. Correct Answer

Community Votes

E
100%

100% of anonymous learners picked answer E. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests how Defender for Cloud Apps stores persistent per-app metadata versus one-time reporting, and the trap is choosing the Cloud Discovery snapshot report because the scenario mentions a security audit.

Microsoft Defender for Cloud Apps lets you mark which Cloud Discovery apps have been audited by applying a custom app tag, because tags persist on the app record and can be filtered inside the cloud app catalog. This page confirms that answer E is correct and explains why reporting and governance options fail.

The most common wrong pick is the Cloud Discovery snapshot report (D): it sounds audit-related, but a report is a static export of discovery data and leaves no per-app marker that the cloud app catalog can display or filter.

Community Discussion (3 comments)

7d01a47 👍 5 Selected: E
By applying custom app tags to the apps detected by Cloud Discovery, you can effectively categorize and track those apps within the cloud app catalog. Custom tags can be used to denote the status of apps, including whether they have been audited, allowing for easy identification and reporting.
Preeb 👍 2
Answer is E
GetEsn 👍 2 Selected: E
https://learn.microsoft.com/en-us/defender-cloud-apps/discovered-app-queries

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Defender for Cloud Apps supports custom app tags as reusable labels that are attached to apps discovered by Cloud Discovery, and the Cloud app catalog can then filter and group apps by those tags. To track an audit, you create a tag such as "Audited", apply it to every app that has been reviewed, and the resulting list of audited apps is displayed directly in the catalog (and in discovered-app queries that filter on the tag). This is exactly the requirement: persistent, catalog-visible tracking of audit status. The community position was unanimous — one learner wrote that "Custom tags can be used to denote the status of apps, including whether they have been audited", and another shared the discovered-app-queries documentation to support tag-based filtering. The source key's E is therefore correct on the merits, not just on vote count.

Why the Other Options Are Wrong

Defining each app as a critical asset (A) is a prioritization signal: criticality tells risk scoring and dashboards which SaaS apps matter most to the business, but it does not record who audited them or expose an "audited" view. Conditional Access App Control (B) is a session proxy that applies real-time access and session policies to sanctioned apps; it neither tags discovered apps nor produces an audit list in the catalog. App governance (C) focuses on OAuth app behavior, permissions and policy alerts for connected apps — it is not a labeling mechanism for Cloud Discovery results. A Cloud Discovery snapshot report (D) is a point-in-time export of discovered apps, traffic and usage; it can be shared with auditors, but it stores no state on the app objects, so the catalog cannot later display which apps were audited.

Community Comment Notes

All recorded learners selected E, so the community consensus and the source key agree here. The most detailed voter explained that tags categorize and track Cloud Discovery apps, noting that they can denote whether an app has been audited, which matches the exam's word "track". Another learner, GetEsn, posted the Microsoft Learn page on discovered-app queries without further explanation, which is the mechanism you would use to list tagged apps programmatically. Preeb added only a one-line confirmation that the answer is E, consistent with the tag-based reasoning above.

Official Reference

Exam Strategy

When an MS-102 scenario asks you to "track", "label" or "display" a per-app state such as audit status in the Cloud app catalog, look for the persistent metadata option (custom app tags) rather than reports, policies or session controls. Reports describe what was discovered at a moment in time; tags change the app record itself, which is what the catalog renders and filters.

Frequently Asked Questions

Why can't a Cloud Discovery snapshot report track which apps were audited?

A snapshot report is a static, point-in-time export of discovery data. It adds no status field to the app itself, so the cloud app catalog cannot later display an audited-apps list from it.

How do custom app tags make audited apps visible in the cloud app catalog?

Tag each app after its audit, for example "Audited", then filter or group the Cloud app catalog or discovered-app queries by that tag to show only the audited apps.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide