Enabling the Microsoft 365 connector and app governance so Defender for Cloud Apps feeds automatic attack disruption
You have a Microsoft 365 E5 subscription. You need to configure Microsoft Defender XDR automatic attack disruption to use signals generated by Microsoft Defender for Cloud Apps. Which two actions should you perform for Defender for Cloud Apps in the Microsoft Defender portal? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Community Votes
67% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Automatic attack disruption that consumes Defender for Cloud Apps signals requires both the Microsoft 365 (Office 365) connector and App Governance to be enabled, which together expose the app/identity signals needed for disruption.
To let Microsoft Defender XDR automatic attack disruption use signals from Defender for Cloud Apps, you must enable the Microsoft 365 connector and turn on app governance for Defender for Cloud Apps — these are the documented prerequisites.
Picking Cloud Discovery user enrichment or file monitoring — those are Defender for Cloud Apps features but are not the documented prerequisites for feeding automatic attack disruption.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The Microsoft Defender XDR automatic attack disruption prerequisites for Defender for Cloud Apps state that you must enable the Microsoft 365 (Office 365) connector and turn on App Governance. These two actions make the Cloud Apps signals available to automatic attack disruption.Why the Other Options Are Wrong
Deploying Cloud Discovery user enrichment (D) and turning on file monitoring (E) are useful Cloud Apps capabilities but are not the two prerequisites for automatic attack disruption. Adding a log collector for automatic log upload (B) is for discovery ingestion, not attack disruption signals.Community Comment Notes
jamspurple and Blasty both cite the configure-attack-disruption documentation, confirming the answer is A (Microsoft 365 connector) and C (App Governance). a_kto_to's ChatGPT answer of C and D is incorrect.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →