Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

You are designing a security operations strategy for a multinational organization. The SOC team needs to correlate alerts from multiple sources including Microsoft Defender for Cloud, Microsoft Sentinel, and third-party firewalls. Which solution should you use as the primary platform for correlation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Sentinel

Microsoft Sentinel (option D) is the correct choice because it is a cloud-native SIEM and SOAR platform designed to ingest, correlate, and analyze security alerts and logs from many sources, including Microsoft Defender for Cloud, Microsoft Sentinel-connected services, and third-party firewalls via data connectors and CEF/Syslog. It provides built-in analytics rules, KQL-based hunting, and incident correlation across multicloud and multiplatform telemetry, which matches the SOC's need for a central correlation platform. Microsoft Defender for Cloud (option A) is a cloud security posture management and workload protection service, not a cross-source SIEM correlation platform. Microsoft 365 Defender (option B) correlates signals primarily across Microsoft 365 and Defender workloads, not third-party firewall telemetry as the primary platform. Azure Monitor (option C) is an infrastructure and application monitoring service, not a security incident correlation SIEM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform (CWPP) that assesses compliance, identifies misconfigurations, and hardens cloud workloads. It does not ingest and correlate arbitrary log data from multiple, unrelated sources to produce security incidents, making it a security control plane rather than a SIEM. While Defender for Cloud can stream alerts into Microsoft Sentinel, it cannot independently perform multi-source SIEM-style correlation across on-premises, third-party, and cloud events.

  • ✗

    Microsoft 365 Defender

    Why it's wrong here

    Microsoft 365 Defender (now Microsoft Defender XDR) unifies endpoint, email, identity, and cloud app detection across the Microsoft 365 ecosystem. It provides incident investigation and automated response within the Microsoft domain, but it lacks connectors for non-Microsoft logs such as firewall events, syslog feeds, and custom application telemetry. Its scope is XDR, not a general-purpose SIEM, so it cannot serve as the central correlation engine for a strategy spanning all log sources.

  • ✗

    Azure Monitor

    Why it's wrong here

    Azure Monitor is an infrastructure telemetry service that collects metrics and logs from Azure, on-premises, and hybrid environments into a centralized workspace. It offers Log Analytics queries, alerts, and visualizations for operational monitoring, but it does not provide security-specific analytics, incident management, or threat-hunting workflows required of a SIEM. Azure Monitor's native focus is on system health and performance, not on ingesting and correlating security events across diverse security tools and data sources.

  • ✓

    Microsoft Sentinel

    Why this is correct

    Microsoft Sentinel is the correct choice because it is a cloud-native SIEM and SOAR platform purpose-built for security operations. It ingests logs from 100+ connectors across Azure, Microsoft 365, third-party security products, on-premises infrastructure, and open-source formats, then uses KQL-based analytics rules and built-in detections to correlate signals into incidents. Sentinel also automates response via playbooks, making it the central multi-source correlation and incident management engine that the other services are not.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.