SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company runs workloads in Azure and Amazon Web Services (AWS). The security team wants a single, unified dashboard to assess the security posture of all cloud resources, get prioritized recommendations for misconfigurations, and enable just-in-time (JIT) virtual machine access across both cloud environments. Which Microsoft security solution should they use?
⚠ Common exam trap
Candidates often confuse Microsoft Defender for Cloud (a CSPM and workload protection platform) with Microsoft Sentinel (a SIEM), leading candidates to choose Sentinel because it also aggregates logs from multiple clouds, but it lacks the specific posture assessment dashboard and JIT VM access features described in the question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Cloud
Microsoft Defender for Cloud is the correct solution because it provides a unified dashboard for assessing security posture across multi-cloud environments, including Azure and AWS. It delivers prioritized recommendations for misconfigurations using the Microsoft cloud security benchmark and supports just-in-time (JIT) VM access to reduce attack surfaces by controlling inbound traffic on demand.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. Its primary function is to collect security data from various sources, detect threats, and automate responses, focusing on security analytics and threat intelligence. It does not natively provide capabilities for continuous security posture assessment across multi-cloud infrastructure or offer just-in-time (JIT) virtual machine access directly.
When this WOULD be correct
A question asking for a cloud-native SIEM to collect security logs, detect threats, and orchestrate automated responses across Azure, AWS, and on-premises would make Microsoft Sentinel the correct answer.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), primarily focused on providing visibility, data control, and threat protection for Software as a Service (SaaS) applications. It helps discover shadow IT, protect sensitive data, and monitor user activity within cloud applications. However, it is not designed for assessing the security posture of underlying Infrastructure as a Service (IaaS) workloads across multiple cloud providers or managing just-in-time access to virtual machines.
When this WOULD be correct
A company wants to discover and control the use of third-party SaaS apps (e.g., Dropbox, Salesforce) across their cloud environments, enforce access policies, and detect anomalous user behavior in those apps.
- ✓
Microsoft Defender for Cloud
Why this is correct
Microsoft Defender for Cloud offers unified security management and threat protection across hybrid and multi-cloud environments, including Azure and AWS. It provides Cloud Security Posture Management (CSPM) for continuous assessment of security configurations, offering recommendations to improve posture. Additionally, its Cloud Workload Protection (CWP) features include just-in-time (JIT) VM access, which significantly reduces the attack surface by only opening management ports when needed.
- ✗
Azure Policy
Why it's wrong here
Azure Policy is an Azure-native service used for creating, assigning, and managing policies to enforce rules and effects on Azure resources, ensuring compliance with organizational standards. While crucial for governance within Azure, it does not inherently provide a unified security posture dashboard for multi-cloud environments like AWS, nor does it offer built-in just-in-time VM access capabilities across different cloud platforms.
When this WOULD be correct
An organization needs to enforce tagging standards, restrict resource types, or audit compliance with corporate policies across Azure subscriptions only, without requiring multi-cloud or security posture assessment features.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Defender for CloudCorrect answer▾
Why this is correct
Microsoft Defender for Cloud offers unified security management and threat protection across hybrid and multi-cloud environments, including Azure and AWS. It provides Cloud Security Posture Management (CSPM) for continuous assessment of security configurations, offering recommendations to improve posture. Additionally, its Cloud Workload Protection (CWP) features include just-in-time (JIT) VM access, which significantly reduces the attack surface by only opening management ports when needed.
✗Microsoft SentinelWrong answer — click to see why▾
Why this is wrong here
Microsoft Sentinel is a SIEM/SOAR solution for threat detection and response, not a unified dashboard for assessing security posture across multi-cloud environments. It does not provide prioritized recommendations for misconfigurations or JIT VM access.
★ When this WOULD be the correct answer
A question asking for a cloud-native SIEM to collect security logs, detect threats, and orchestrate automated responses across Azure, AWS, and on-premises would make Microsoft Sentinel the correct answer.
Why candidates choose this
Candidates may confuse Sentinel's log aggregation and alerting capabilities with the posture management and recommendation features of Defender for Cloud, especially since both are part of the Microsoft security portfolio.
✗Microsoft Defender for Cloud AppsWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) focused on SaaS application usage and shadow IT, not a unified dashboard for assessing security posture across Azure and AWS with JIT VM access.
★ When this WOULD be the correct answer
A company wants to discover and control the use of third-party SaaS apps (e.g., Dropbox, Salesforce) across their cloud environments, enforce access policies, and detect anomalous user behavior in those apps.
Why candidates choose this
Candidates may confuse 'cloud apps' with 'cloud resources' and think Defender for Cloud Apps provides cross-cloud posture management, but it actually focuses on SaaS application governance, not infrastructure security.
✗Azure PolicyWrong answer — click to see why▾
Why this is wrong here
Azure Policy enforces and audits compliance rules across Azure resources but does not provide a unified dashboard for AWS, prioritized recommendations for misconfigurations, or JIT VM access across multi-cloud environments.
★ When this WOULD be the correct answer
An organization needs to enforce tagging standards, restrict resource types, or audit compliance with corporate policies across Azure subscriptions only, without requiring multi-cloud or security posture assessment features.
Why candidates choose this
Candidates may confuse Azure Policy's compliance enforcement with security posture management, or think it can be extended to AWS via Azure Arc, but it lacks the unified dashboard and JIT capabilities described.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security posture
An organization's overall cybersecurity strength, including policies, controls, and readiness to defend against and respond to threats.
Key term
Defender for Cloud
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides unified security management and threat protection across hybrid and multi-cloud environments.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.