Courseiva
mediumMatching

SC-100 Practice Question: Match each security operations tool to its…

Match each security operations tool to its primary function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Security information and event management

Extended detection and response (XDR)

Cloud security posture management

Identity risk detection and remediation

Data governance and compliance

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Sentinel: Provides intelligent security analytics and threat intelligence across the enterprise, with log ingestion and automated response.

These tools form the Microsoft security operations stack. Sentinel handles SIEM/SOAR, Defender XDR provides XDR across domains, and Defender for Cloud secures cloud workloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Sentinel: Provides intelligent security analytics and threat intelligence across the enterprise, with log ingestion and automated response.

    Why this is correct

    Microsoft Sentinel is a cloud-native SIEM and SOAR platform that ingests logs from any source—including Microsoft 365, Azure, and third-party appliances—into a unified workspace. It uses built-in analytics, UEBA, and threat intelligence to detect complex threats, then powers automated playbooks with Azure Logic Apps for orchestrated response. This aligns with the matching task's intent that Sentinel's primary function is enterprise-wide log ingestion, detection, and automated remediation, not identity protection.

  • ✗

    Microsoft Sentinel: Monitors and protects identities by detecting sign-in risks and providing conditional access policies.

    Why it's wrong here

    Monitoring sign-in risk and enforcing conditional access are core capabilities of Microsoft Entra ID Protection (formerly Azure AD Identity Protection), not Sentinel. Sentinel ingests identity-related logs and can receive alerts from Entra ID, but it does not natively evaluate risk events or issue conditional access policies. Pairing the wrong description with Sentinel confuses the SIEM's analytics role with the identity security platform's preventive controls.

  • ✓

    Microsoft Defender XDR: Delivers comprehensive incident detection, investigation, and response across endpoints, email, identities, and cloud apps.

    Why this is correct

    Microsoft Defender XDR is a true extended detection and response solution that fuses signals from Defender for Endpoint, Office 365, Identity (now Entra ID Protection), and Defender for Cloud Apps into a single incident queue. Its correlation engine automatically groups related alerts across domains into one incident, giving security teams a unified timeline and guided remediation actions. This cross-domain investigation and response is what distinguishes XDR from a posture or SIEM tool.

  • ✗

    Microsoft Defender XDR: Provides security posture management for cloud environments.

    Why it's wrong here

    Security posture management for cloud environments is the hallmark of Microsoft Defender for Cloud, particularly its CSPM capabilities that assess compliance, identify misconfigurations, and generate hardening recommendations. While Defender XDR uses Defender for Cloud's alerts as one input, its own primary function is incident detection and response, not ongoing posture assessments. Therefore, assigning this description to Defender XDR misattributes the specialized role of a cloud security posture tool.

  • ✓

    Microsoft Defender for Cloud: Helps protect cloud workloads by providing security recommendations, vulnerability assessments, and advanced threat protection.

    Why this is correct

    Microsoft Defender for Cloud is both a CSPM and a cloud workload protection platform (CWPP), continuously evaluating Azure resources, subscriptions, and hybrid workloads against security baselines. It delivers actionable recommendations via a secure score, performs vulnerability assessments using built-in scanners, and applies advanced threat protection such as just-in-time VM access and adaptive application controls. These capabilities focus specifically on protecting and hardening cloud workloads as the primary function, aligning with the description given.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.