Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company runs workloads in Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP). The security team needs a single, unified dashboard to continuously assess the security posture of all cloud resources, identify misconfigurations, and receive prioritized recommendations for remediation. Which Microsoft security solution should they use?

⚠ Common exam trap

Test-takers frequently confuse a cloud security posture management (CSPM) tool (Defender for Cloud) with a cloud access security broker (CASB) or a SIEM/SOAR solution, leading candidates to pick Defender for Cloud Apps or Sentinel because they also provide security visibility, but for different use cases.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Cloud

Microsoft Defender for Cloud is the correct solution because it provides a unified cloud security posture management (CSPM) dashboard that continuously assesses resources across Azure, AWS, and GCP. It identifies misconfigurations against industry benchmarks (e.g., CIS, NIST) and delivers prioritized, actionable recommendations to remediate risks, directly meeting the requirement for a single dashboard across multi-cloud environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Cloud

    Why this is correct

    Microsoft Defender for Cloud is the correct solution because it provides comprehensive Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) across multi-cloud environments, including Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP). It centralizes security posture assessment, identifies misconfigurations, and offers prioritized recommendations for resources in both Azure and AWS from a single pane of glass, ensuring consistent security across the company's diverse infrastructure.

  • Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), primarily focusing on discovering, monitoring, and controlling access to cloud applications (SaaS) and services, as well as protecting sensitive data within them. While crucial for application-level security and compliance, it does not provide native security posture management or threat protection for the underlying infrastructure and workloads running directly on IaaS platforms like Azure or AWS.

    When this WOULD be correct

    A company wants to discover and control the use of third-party SaaS applications (e.g., Dropbox, Salesforce) accessed by employees, enforce access policies, and detect anomalous behavior in cloud app usage. In that scenario, Microsoft Defender for Cloud Apps would be the correct solution.

  • Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It aggregates security data from various sources, including cloud platforms, applications, and on-premises systems, to detect threats, investigate alerts, and automate responses. While it can ingest security findings from posture management tools, Sentinel itself does not natively perform the initial security posture assessment or configuration analysis of cloud environments like Azure or AWS.

    When this WOULD be correct

    A company needs a cloud-native SIEM to collect security data from all cloud environments, detect threats, and orchestrate automated responses across Azure, AWS, and GCP. The question emphasizes threat detection and incident response rather than posture management.

  • Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint is an enterprise endpoint security platform designed to help organizations prevent, detect, investigate, and respond to advanced threats on devices such as workstations, servers, and mobile devices. Its core functionality revolves around Endpoint Detection and Response (EDR) and vulnerability management for operating systems, not assessing the security configurations or posture of cloud infrastructure services provided by Azure or AWS themselves.

    When this WOULD be correct

    A question asking for a solution to protect endpoints (e.g., laptops, servers) from threats like malware, with capabilities for endpoint detection and response (EDR), and integration with Microsoft 365 Defender.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft Defender for CloudCorrect answer

Why this is correct

Microsoft Defender for Cloud is the correct solution because it provides comprehensive Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) across multi-cloud environments, including Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP). It centralizes security posture assessment, identifies misconfigurations, and offers prioritized recommendations for resources in both Azure and AWS from a single pane of glass, ensuring consistent security across the company's diverse infrastructure.

Microsoft Defender for Cloud AppsWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) focused on SaaS application usage and shadow IT discovery, not on assessing the security posture of IaaS/PaaS resources across multiple clouds like AWS and GCP.

★ When this WOULD be the correct answer

A company wants to discover and control the use of third-party SaaS applications (e.g., Dropbox, Salesforce) accessed by employees, enforce access policies, and detect anomalous behavior in cloud app usage. In that scenario, Microsoft Defender for Cloud Apps would be the correct solution.

Why candidates choose this

The name 'Defender for Cloud Apps' suggests it covers cloud security broadly, and candidates may confuse it with a multi-cloud posture management tool, not realizing its focus is on SaaS application governance rather than infrastructure security.

Microsoft SentinelWrong answer — click to see why

Why this is wrong here

Microsoft Sentinel is a SIEM/SOAR solution for security analytics and threat detection across the enterprise, not a unified dashboard for continuous cloud security posture assessment and misconfiguration identification across multi-cloud environments.

★ When this WOULD be the correct answer

A company needs a cloud-native SIEM to collect security data from all cloud environments, detect threats, and orchestrate automated responses across Azure, AWS, and GCP. The question emphasizes threat detection and incident response rather than posture management.

Why candidates choose this

Candidates may confuse Sentinel's ability to ingest data from multiple clouds with the specific function of assessing security posture and providing remediation recommendations, which is Defender for Cloud's role.

Microsoft Defender for EndpointWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Endpoint focuses on endpoint devices (e.g., workstations, servers) and does not provide a unified dashboard for assessing security posture across multi-cloud environments (Azure, AWS, GCP).

★ When this WOULD be the correct answer

A question asking for a solution to protect endpoints (e.g., laptops, servers) from threats like malware, with capabilities for endpoint detection and response (EDR), and integration with Microsoft 365 Defender.

Why candidates choose this

Candidates may confuse 'Defender for Endpoint' with 'Defender for Cloud' due to similar naming, or assume it covers cloud resources because it can protect cloud-hosted VMs, but it lacks multi-cloud posture management.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.