Design solutions that align with security best practices and priorities →mediumMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design solutions that align with security best practices and priorities
A security architect needs to design a solution that provides a unified view of security alerts from multiple clouds (Azure, AWS, GCP) and on-premises systems. The solution must also support automated response using playbooks. Which Microsoft service should they use?
⚠ Common exam trap
A common mix-up: candidates confuse Microsoft Defender for Cloud (a CSPM tool) with Microsoft Sentinel (a SIEM/SOAR), as both appear in the Azure portal and deal with security alerts, but only Sentinel provides native multi-cloud SIEM ingestion and automated playbook orchestration for cross-cloud incident response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel
Microsoft Sentinel is the correct choice because it is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution that ingests security alerts from multiple clouds (Azure, AWS, GCP) and on-premises systems via connectors. It supports automated response through playbooks built on Azure Logic Apps, enabling unified alert management and remediation workflows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender XDR
Why it's wrong here
Microsoft Defender XDR is a unified threat protection suite that correlates signals from Microsoft 365 Defender, Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps. It does ingest data from those Microsoft security products, but it is not a SIEM/SOAR platform and lacks native support for ingesting third-party multi-cloud logs (e.g., from AWS CloudTrail or Google Cloud Audit Logs) or on-premises sources like syslog. Its focus is on incident detection and response across the Microsoft ecosystem, not centralized multi-cloud log aggregation. Therefore, it does not satisfy the requirement for a multi-cloud SIEM/SOAR solution.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWP) that provides security recommendations, vulnerability assessments, and workload protections for Azure, hybrid, and other cloud resources. While it does integrate with Microsoft Sentinel as a data source, it is not designed to collect and correlate log data from diverse multi-cloud sources to enable search, investigation, and automated response playbooks. It focuses on hardening configurations and protecting workloads, not on event-driven security operations like a SIEM. Its native analytics and workflow automation are limited to security posture and compliance, missing the multi-cloud SIEM capabilities required.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview is a data governance, information protection, and cataloging solution that discovers, classifies, and manages sensitive data across on-premises and multi-cloud estates. It offers data loss prevention, data lifecycle management, and records management, but it does not ingest audit logs, security alerts, or network telemetry into a central time-based repository for threat detection. Purview lacks SIEM capabilities like KQL queries, correlation rules, and incident investigation, and it has no SOAR automation for responding to security events. Therefore, Purview addresses data governance and compliance, not the operational security monitoring required for a SIEM/SOAR solution.
- ✓
Microsoft Sentinel
Why this is correct
Microsoft Sentinel is a cloud-native SIEM and SOAR that natively ingests data from Azure and, via built-in connectors, from AWS, Google Cloud, other SaaS platforms, and on-premises sources such as syslog and CEF, allowing centralized multi-cloud log collection. Its analytical rules use Kusto Query Language to detect suspicious activity and trigger automated response playbooks built on Azure Logic Apps, providing real-time containment like device isolation or account disablement. Sentinel's architecture includes Common Event Format (CEF) and Syslog agents for on-premises, plus API connectors for AWS CloudTrail and GCP, making it the only option that fulfills the full multi-cloud SIEM/SOAR requirement with integrated UEBA and threat intelligence.
Go deeper
Related to this question
About these practice questions
One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.