SC-300 Practice Question 3466

Exam: SC-300
Domain: Plan and implement workload identities
Difficulty: hard
You are auditing high-risk applications in your tenant. You need to identify service principals that have been granted high-privilege permissions (such as Directory.ReadWrite.All or AppRoleAssignment.ReadWrite.All). Which tool provides automated risk visibility?

Answer Options

A
App Governance in Microsoft Defender for Cloud Apps
B
Exchange Message Trace delivery reports
C
Local computer Device Manager
D
Azure Network Watcher packet capture

Correct Answer

A: App Governance in Microsoft Defender for Cloud Apps

Explanation

App Governance in Microsoft Defender for Cloud Apps monitors OAuth apps, identifies over-privileged or anomalous API usage, and flags high-risk app behaviors.