Enabling the Microsoft 365 connector and app governance so Defender for Cloud Apps feeds automatic attack disruption

Configure automation for Microsoft Defender XDR and Microsoft Sentinel
Answer Correct answer: A, C — Automatic attack disruption needs the Microsoft 365 connector and App Governance enabled in Defender for Cloud Apps.

You have a Microsoft 365 E5 subscription. You need to configure Microsoft Defender XDR automatic attack disruption to use signals generated by Microsoft Defender for Cloud Apps. Which two actions should you perform for Defender for Cloud Apps in the Microsoft Defender portal? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  1. Enable the Microsoft 365 connector. Correct Answer
  2. Add a log collector for automatic log upload.
  3. Turn on app governance. Correct Answer
  4. Deploy Cloud Discovery user enrichment.
  5. From Information protection, enable file monitoring.

Community Votes

AC
67%
CD
33%

67% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Automatic attack disruption that consumes Defender for Cloud Apps signals requires both the Microsoft 365 (Office 365) connector and App Governance to be enabled, which together expose the app/identity signals needed for disruption.

To let Microsoft Defender XDR automatic attack disruption use signals from Defender for Cloud Apps, you must enable the Microsoft 365 connector and turn on app governance for Defender for Cloud Apps — these are the documented prerequisites.

Picking Cloud Discovery user enrichment or file monitoring — those are Defender for Cloud Apps features but are not the documented prerequisites for feeding automatic attack disruption.

Community Discussion (3 comments)

a_kto_to 👍 1 Selected: CD
As per chatGTP: ✅ Final Answer: ✔ C. Turn on App Governance ✔ D. Deploy Cloud Discovery User Enrichment Would you like a guide on enabling these in Defender for Cloud Apps? 😊
jamspurple 👍 1 Selected: AC
A and C https://learn.microsoft.com/en-us/defender-xdr/configure-attack-disruption#microsoft-defender-for-cloud-apps-prerequisites
Blasty 👍 1 Selected: AC
Two actions must be performed: - Microsoft Office 365 connector - App Governance must be turned on https://learn.microsoft.com/en-us/defender-xdr/configure-attack-disruption

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The Microsoft Defender XDR automatic attack disruption prerequisites for Defender for Cloud Apps state that you must enable the Microsoft 365 (Office 365) connector and turn on App Governance. These two actions make the Cloud Apps signals available to automatic attack disruption.

Why the Other Options Are Wrong

Deploying Cloud Discovery user enrichment (D) and turning on file monitoring (E) are useful Cloud Apps capabilities but are not the two prerequisites for automatic attack disruption. Adding a log collector for automatic log upload (B) is for discovery ingestion, not attack disruption signals.

Community Comment Notes

jamspurple and Blasty both cite the configure-attack-disruption documentation, confirming the answer is A (Microsoft 365 connector) and C (App Governance). a_kto_to's ChatGPT answer of C and D is incorrect.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide