Design security operations, identity, and compliance capabilities →hardMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization is a multi-national corporation that uses Microsoft 365 E5 and Azure. You need to design a security operations center (SOC) to detect and respond to threats across identities, endpoints, and cloud apps. The SOC team will use a single pane of glass for incident management. Requirements: (1) Centralize alerts from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps, (2) Automate incident response playbooks, (3) Use advanced hunting across all data sources, (4) Integrate with external threat intelligence feeds, (5) Provide role-based access control for SOC analysts. Which Microsoft solution should you implement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel
Microsoft Sentinel is a cloud-native SIEM/SOAR that ingests alerts from all Microsoft Defender products, supports automation playbooks, advanced hunting via KQL, threat intelligence connectors, and RBAC. Option A is wrong because the Microsoft 365 Defender portal provides visibility across Defender products but lacks the full SIEM/SOAR capabilities needed for automation, advanced hunting, and external threat intelligence integration. Option C is wrong because Microsoft Purview Compliance Manager is a data governance and compliance solution, not a security operations platform. Option D is wrong because Microsoft Defender for Cloud is a cloud workload protection platform (CWPP) that does not serve as a unified SIEM across identities, endpoints, and apps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft 365 Defender portal
Why it's wrong here
The Microsoft 365 Defender portal provides unified visibility across Defender products but lacks native SOAR automation, advanced hunting with KQL across all data sources, and seamless external threat intelligence integration. It is not a full SIEM/SOAR solution.
- ✓
Microsoft Sentinel
Why this is correct
Microsoft Sentinel is the only option that functions as a true cloud-native SIEM/SOAR, ingesting security telemetry from across Microsoft Defender products, Azure services, and third-party sources. It provides automation playbooks for incident response, advanced hunting with Kusto Query Language (KQL), built-in threat intelligence connectors, and role-based access control for the SOC. This centralized architecture is essential for aggregating identity, endpoint, and app signals into a single detection and response workflow, meeting the requirement for a security operations center.
- ✗
Microsoft Purview Compliance Manager
Why it's wrong here
Microsoft Purview Compliance Manager is designed specifically for regulatory compliance and data governance, offering assessments, controls, and automated testing for standards such as ISO 27001 and GDPR. It does not ingest operational security telemetry, cannot execute automated incident response playbooks, and lacks the KQL-based hunting and threat intelligence capabilities required of a SIEM/SOAR. While it can show scorecards and evidence, it is fundamentally a compliance posture tool, not a security operations center platform.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is a cloud workload protection platform (CWPP) that provides security recommendations and threat protection for cloud resources, but it does not serve as a unified SOC tool for identity, endpoint, and app security across hybrid environments.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.