Microsoft365テナントがあります。 Azure Active Directory(Azure AD)テナントは、オンプレミスのActiveDirectoryドメインに同期します。 ユーザーは、会社のハードウェアファイアウォールを使用してインターネットに接続します。ユーザーは、ActiveDirectoryの資格情報を使用してファイアウォールに対して認証します。 AzureADを使用して外部アプリケーションへのアクセスを管理することを計画しています。 管理されていない外部アプリケーションとそれらにアクセスするユーザーのリストを作成するには、ファイアウォールログを使用する必要があります。 情報を収集するために何を使用する必要がありますか?
正解:C
According to the Microsoft SC-300: Identity and Access Administrator study materials and Microsoft Learn modules under "Implement and manage Cloud App Security (Microsoft Defender for Cloud Apps)", the Cloud App Discovery feature in Microsoft Cloud App Security (now called Microsoft Defender for Cloud Apps) is designed to identify and analyze the use of shadow IT - unmanaged or unsanctioned applications accessed by users within the organization. Cloud App Discovery collects logs from network appliances such as firewalls, proxies, or Secure Web Gateways (SWGs). Administrators upload these logs into Cloud App Security or configure continuous log collection through automatic log uploaders. The service then parses and analyzes the data to detect which external applications are being accessed and which users are using them. In this scenario, since users authenticate to the firewall with their on-premises Active Directory credentials, the firewall logs will contain user information and the external applications being accessed. By importing these logs into Cloud App Discovery, administrators can generate a detailed list of unmanaged (unsanctioned) external applications and identify the specific users connecting to them. Microsoft documentation explicitly states: "Cloud App Discovery analyzes traffic logs to identify all cloud applications used in your organization. It provides information about app usage, users, IP addresses, and risk levels to help you assess shadow IT." Hence, the correct and verified answer - based on official SC-300 curriculum and Azure AD Identity Governance content - is Cloud App Discovery in Microsoft Cloud App Securit