SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Defender for Cloud to secure a multi-cloud environment including Azure, AWS, and GCP. You need to design a solution that centralizes security alerts and automates remediation across all clouds. Which security operations capability should you prioritize?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Microsoft Sentinel as a single SIEM and SOAR platform with connectors for AWS and GCP
Microsoft Sentinel is the correct choice because it functions as a cloud-native SIEM and SOAR platform that can ingest security alerts from Azure, AWS, and GCP via native data connectors, then centralize them and drive automated remediation through playbooks (Logic Apps). This directly satisfies the requirement to centralize alerts and automate remediation across a multi-cloud estate. Option B is only partially relevant: Defender for Cloud's multi-cloud connector aggregates posture and alert data but does not provide the full SIEM/SOAR automation capability Sentinel delivers. Option A (Purview Compliance Manager) is for regulatory compliance assessments, not security operations, and Option D (Defender for Identity) only monitors identity signals in hybrid Active Directory environments, not multi-cloud alert centralization or remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Microsoft Purview Compliance Manager for regulatory assessments
Why it's wrong here
Microsoft Purview Compliance Manager is a compliance and data governance tool that maps controls to regulatory frameworks such as GDPR, ISO 27001, and SOC 2, producing a compliance score and evidence-based assessments. It does not ingest security alerts, correlate attack indicators, or provide automated incident response, and is therefore not a multi-cloud security operations platform.
- ✗
Enable Microsoft Defender for Cloud's multi-cloud connector to aggregate alerts
Why it's wrong here
Defender for Cloud's multi-cloud connector (e.g., AWS Security Hub or GCP Security Command Center) ingests native cloud alerts into a single dashboard, enabling cross-platform CSPM and workload protection features. However, it is not a replacement for a SIEM/SOAR: it provides limited threat hunting (no KQL query language over historical logs), no user/entity behavioral analytics across all data sources, and automation is largely restricted to Defender policy remediation, not orchestrating full response playbooks across heterogeneous sources.
- ✓
Use Microsoft Sentinel as a single SIEM and SOAR platform with connectors for AWS and GCP
Why this is correct
Microsoft Sentinel is a cloud-native SIEM and SOAR that centralizes security telemetry from Azure, AWS, and GCP via native connectors, such as AWS CloudTrail/Security Hub and the GCP Pub/Sub-based connector, into a single Log Analytics workspace. It empowers analysts to run KQL-based hunt queries across all clouds, create custom analytics rules for multi-cloud attack detection, and use Automation rules and Logic Apps playbooks to orchestrate response. This provides true unified incident management and automated remediation across heterogeneous environments, far beyond what individual cloud security tools offer.
- ✗
Deploy Microsoft Defender for Identity to monitor hybrid identities
Why it's wrong here
Microsoft Defender for Identity focuses specifically on detecting identity-based attacks targeting Active Directory, such as Kerberoasting, Overpass-the-Hash, and privilege escalation attempts, by analyzing on-premises domain controllers. While it can forward alerts to Microsoft Sentinel for correlation, it does not ingest, aggregate, or analyze security events from AWS or GCP cloud workloads, and its monitoring scope is limited to hybrid identity infrastructure rather than multi-cloud security operations.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.