Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Your organization wants to implement a security information and event management (SIEM) solution that can ingest logs from multiple sources, including on-premises servers, Azure resources, and third-party SaaS applications. Which Microsoft service should you choose?

⚠ Common exam trap

Many exam-takers confuse Azure Monitor with a SIEM because it collects logs and metrics, but it lacks the security-specific correlation, threat intelligence integration, and incident management features that define a true SIEM like Microsoft Sentinel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Sentinel

Microsoft Sentinel is the correct choice because it is a cloud-native SIEM solution specifically designed to ingest logs from diverse sources, including on-premises servers, Azure resources, and third-party SaaS applications, using built-in connectors for over 100 data sources. It provides centralized security analytics, threat detection, and incident response, making it the appropriate service for this multi-source log ingestion requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Purview

    Why it's wrong here

    Microsoft Purview is a data governance, compliance, and risk management solution, not a security information and event management (SIEM) platform. It focuses on data classification, sensitivity labeling, data lineage, and policy enforcement such as data loss prevention (DLP). Purview lacks the centralized log ingestion, real-time correlation, and incident management capabilities required for a SOC to detect and respond to security threats across an enterprise.

  • Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud provides cloud security posture management (CSPM) and cloud workload protection (CWPP), offering security recommendations, vulnerability assessments, and adaptive threat protection for cloud resources. While it can ingest some security alerts and produce findings, it is not a SIEM because it does not aggregate and correlate raw logs from diverse on-premises and third-party sources, nor does it provide a unified querying and incident-handling workflow for the entire organization.

  • Microsoft Sentinel

    Why this is correct

    Microsoft Sentinel is the correct answer because it is a scalable, cloud-native SIEM and SOAR service that ingests logs from a wide range of sources, including Microsoft 365, Azure, third-party apps, and on-premises systems. It uses Kusto Query Language (KQL) for advanced hunting and custom analytics, and it provides built-in connectors for many security products. Sentinel centralizes security data, triggers alerts based on correlation rules, and supports automated response playbooks for end-to-end incident management.

  • Azure Monitor

    Why it's wrong here

    Azure Monitor is designed for IT performance and operational monitoring, collecting metrics, activity logs, and application telemetry to track resource health and availability. It lacks the security-specific capabilities of a SIEM, such as ingesting and correlating security event logs from multiple entities, maintaining a security data warehouse for investigation, and providing incident management with built-in analyst workflows. While Azure Monitor can store log data, it is not a substitute for a dedicated security information and event management platform.

About these practice questions

Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.