SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company maintains an on-premises Active Directory environment with over 10,000 domain-joined computers. The security team is concerned about advanced attacks that use stolen credentials to move laterally, such as pass-the-hash attacks or DCSync attacks targeting domain controllers. They need a solution that monitors on-premises Active Directory traffic and event logs to detect these identity-based threats and provides alerts for investigation. Which Microsoft security solution should they deploy?
⚠ Common exam trap
Test-takers frequently confuse Microsoft Defender for Identity with Microsoft Sentinel, assuming that a SIEM is always the best choice for threat detection, but Sentinel lacks the specialized Active Directory protocol-level analysis and behavioral models that Defender for Identity provides natively.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Identity
Microsoft Defender for Identity is the correct solution because it is specifically designed to monitor on-premises Active Directory traffic and event logs to detect advanced identity-based threats like pass-the-hash, pass-the-ticket, and DCSync attacks. It uses behavioral analytics and machine learning to identify suspicious activities, such as anomalous Kerberos ticket requests or replication attempts, and provides real-time alerts for investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Identity
Why this is correct
Microsoft Defender for Identity is purpose-built to protect hybrid identity environments, specifically monitoring on-premises Active Directory domain controllers. It deploys lightweight sensors directly on domain controllers to profile network traffic and event logs, detecting advanced threats like Pass-the-Hash, Golden Ticket attacks, and DCSync. This specialized focus allows it to identify suspicious user and entity behavior patterns indicative of compromise within the AD infrastructure, providing critical alerts for security teams.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Microsoft Defender for Endpoint provides unified endpoint security for devices across various platforms, offering capabilities like next-generation antivirus, endpoint detection and response (EDR), and vulnerability management. While it protects servers that might host Active Directory, its primary function is securing individual endpoints from malware and exploits, not specifically analyzing Active Directory protocol traffic or detecting identity-based attacks within the AD environment itself. It focuses on device-level threats rather than domain-wide identity compromise.
When this WOULD be correct
A company needs to detect and respond to advanced threats on endpoints, such as fileless malware, ransomware, or suspicious PowerShell execution, and requires endpoint detection and response (EDR) capabilities for its domain-joined computers.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), extending visibility and control over cloud applications and services. Its capabilities include discovering shadow IT, protecting sensitive data in cloud apps, and detecting anomalous behavior within SaaS applications. This solution is designed exclusively for cloud environments and SaaS applications, making it unsuitable for monitoring or protecting an on-premises Active Directory environment.
When this WOULD be correct
A company uses multiple SaaS applications (e.g., Office 365, Salesforce) and needs to detect anomalous user behavior, data exfiltration, or compromised accounts in the cloud. They require a Cloud Access Security Broker (CASB) to monitor and control cloud app usage.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It aggregates security data from numerous sources, including on-premises systems and cloud services, for centralized analysis, threat detection, and automated response. While Sentinel can ingest Active Directory logs and alerts from other Defender products, it is a general-purpose platform for security operations, not the specialized detection engine for identity-based threats originating directly from on-premises AD traffic.
When this WOULD be correct
A question where the requirement is to centralize security logs from multiple sources (including on-premises AD, cloud apps, and endpoints) into a single platform for advanced threat hunting, correlation, and automated response across the entire environment. For example: 'The security team needs a unified SIEM solution to collect logs from on-premises AD, Azure AD, and third-party firewalls for incident investigation and automated playbooks.'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Defender for IdentityCorrect answer▾
Why this is correct
Microsoft Defender for Identity is purpose-built to protect hybrid identity environments, specifically monitoring on-premises Active Directory domain controllers. It deploys lightweight sensors directly on domain controllers to profile network traffic and event logs, detecting advanced threats like Pass-the-Hash, Golden Ticket attacks, and DCSync. This specialized focus allows it to identify suspicious user and entity behavior patterns indicative of compromise within the AD infrastructure, providing critical alerts for security teams.
✗Microsoft Defender for EndpointWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Endpoint focuses on endpoint devices (e.g., malware, vulnerabilities) and does not natively monitor on-premises Active Directory traffic or event logs for identity-based attacks like pass-the-hash or DCSync.
★ When this WOULD be the correct answer
A company needs to detect and respond to advanced threats on endpoints, such as fileless malware, ransomware, or suspicious PowerShell execution, and requires endpoint detection and response (EDR) capabilities for its domain-joined computers.
Why candidates choose this
Candidates may confuse endpoint security with identity security, assuming that protecting domain-joined computers automatically covers Active Directory threat detection.
✗Microsoft Defender for Cloud AppsWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Cloud Apps focuses on securing cloud applications and detecting threats in cloud services, not on-premises Active Directory traffic or lateral movement attacks like pass-the-hash or DCSync.
★ When this WOULD be the correct answer
A company uses multiple SaaS applications (e.g., Office 365, Salesforce) and needs to detect anomalous user behavior, data exfiltration, or compromised accounts in the cloud. They require a Cloud Access Security Broker (CASB) to monitor and control cloud app usage.
Why candidates choose this
Candidates may think 'cloud apps' includes Active Directory in the cloud (Azure AD) or assume the solution covers all identity threats, but it is specifically for cloud application security, not on-prem AD monitoring.
✗Microsoft SentinelWrong answer — click to see why▾
Why this is wrong here
Microsoft Sentinel is a SIEM/SOAR platform that ingests logs from multiple sources, but it does not natively monitor on-premises Active Directory traffic or detect identity-based attacks like pass-the-hash or DCSync without additional data connectors and analytics rules. The question specifically asks for a solution that monitors on-premises AD traffic and event logs for identity threats, which is the core function of Defender for Identity, not Sentinel.
★ When this WOULD be the correct answer
A question where the requirement is to centralize security logs from multiple sources (including on-premises AD, cloud apps, and endpoints) into a single platform for advanced threat hunting, correlation, and automated response across the entire environment. For example: 'The security team needs a unified SIEM solution to collect logs from on-premises AD, Azure AD, and third-party firewalls for incident investigation and automated playbooks.'
Why candidates choose this
Candidates may think Sentinel is the most comprehensive solution and assume it can directly monitor AD traffic, not realizing it requires additional configuration and data sources, while Defender for Identity is purpose-built for on-premises AD identity threats.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Pass-the-hash
Pass-the-hash is a cyberattack where an attacker captures the hash of a user's password and uses it to authenticate to other systems without ever knowing the actual password.
Key term
Event
An event is any identifiable occurrence or action in a computer system, network, or application that can be logged, monitored, or analyzed for security or operational purposes.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.