SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company's security operations center wants to detect advanced attacks targeting their on-premises Active Directory, such as Kerberos Golden Ticket attacks, pass-the-hash, and skeleton key malware. They need a solution that monitors domain controller traffic, correlates with entity behavior, and integrates with Microsoft Sentinel for incident response. Which Microsoft security solution should they deploy?
⚠ Common exam trap
Many candidates confuse Microsoft Sentinel as the detection tool itself, when in fact Sentinel is the aggregation and response platform, while Defender for Identity is the dedicated on-premises AD threat detection solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Identity
Microsoft Defender for Identity (MDI) is the correct solution because it is specifically designed to monitor on-premises Active Directory traffic, including domain controller network traffic, and uses entity behavior analytics to detect advanced attacks like Kerberos Golden Ticket, pass-the-hash, and skeleton key malware. It integrates natively with Microsoft Sentinel to enable automated incident response and investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Identity
Why this is correct
Microsoft Defender for Identity (MDI) is specifically designed to protect hybrid identity environments by monitoring on-premises Active Directory domain controllers. It leverages network traffic analysis and security event log inspection to detect sophisticated identity-based attacks, such as pass-the-hash, Golden Ticket, and reconnaissance activities. MDI's behavioral analytics engine establishes baselines for user and entity behavior, enabling it to identify anomalous activities indicative of advanced persistent threats targeting credentials and domain infrastructure. This makes it the ideal solution for a Security Operations Center (SOC) seeking to detect advanced identity-based threats within their on-premises AD.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Defender for Endpoint focuses on endpoint devices (Windows, macOS, Linux) and provides antivirus, EDR, and threat investigation. While it can detect some attacks on endpoints, it does not directly monitor domain controller traffic or AD-specific protocols like Kerberos.
When this WOULD be correct
A company needs to detect and respond to advanced malware and fileless attacks on endpoints, such as ransomware or exploit kits, and requires integration with Microsoft Sentinel for incident response.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is a comprehensive solution focused on securing cloud resources and workloads across multi-cloud environments, including Azure, AWS, and GCP. Its primary functions include Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP), providing recommendations and threat detection for cloud-native services, virtual machines, and containers. However, it does not provide direct monitoring or threat detection capabilities for on-premises Active Directory infrastructure. Therefore, it is not the appropriate tool for detecting advanced identity-based threats originating within a company's on-premises domain controllers.
When this WOULD be correct
A company wants to assess the security posture of their Azure and hybrid cloud resources, detect misconfigurations, and protect against cloud-specific threats like compromised storage accounts or vulnerable VMs. They need a Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP).
- ✗
Microsoft Sentinel
Why it's wrong here
Sentinel is a SIEM/SOAR solution that can ingest logs from various sources, including Defender for Identity. However, Sentinel itself does not directly detect identity-based attacks; it relies on other security solutions for detection. The scenario requires a solution that actively monitors AD, which is Defender for Identity.
When this WOULD be correct
A company needs a cloud-native SIEM to centralize security logs from multiple sources (e.g., firewalls, servers, cloud apps) and automate incident response. The question would specify that the goal is log aggregation and orchestration, not direct AD attack detection.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Defender for IdentityCorrect answer▾
Why this is correct
Microsoft Defender for Identity (MDI) is specifically designed to protect hybrid identity environments by monitoring on-premises Active Directory domain controllers. It leverages network traffic analysis and security event log inspection to detect sophisticated identity-based attacks, such as pass-the-hash, Golden Ticket, and reconnaissance activities. MDI's behavioral analytics engine establishes baselines for user and entity behavior, enabling it to identify anomalous activities indicative of advanced persistent threats targeting credentials and domain infrastructure. This makes it the ideal solution for a Security Operations Center (SOC) seeking to detect advanced identity-based threats within their on-premises AD.
✗Microsoft Defender for EndpointWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Endpoint focuses on endpoint devices (workstations, servers) and does not monitor domain controller traffic or detect Active Directory-specific attacks like Golden Ticket or skeleton key.
★ When this WOULD be the correct answer
A company needs to detect and respond to advanced malware and fileless attacks on endpoints, such as ransomware or exploit kits, and requires integration with Microsoft Sentinel for incident response.
Why candidates choose this
Candidates may confuse endpoint protection with identity protection, assuming that 'Defender for Endpoint' covers all security scenarios including Active Directory attacks.
✗Microsoft Defender for CloudWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Cloud is designed for protecting cloud workloads (IaaS, PaaS, and hybrid) and does not monitor on-premises Active Directory traffic or detect Kerberos attacks like Golden Ticket or pass-the-hash.
★ When this WOULD be the correct answer
A company wants to assess the security posture of their Azure and hybrid cloud resources, detect misconfigurations, and protect against cloud-specific threats like compromised storage accounts or vulnerable VMs. They need a Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP).
Why candidates choose this
Candidates may confuse 'Defender for Cloud' with identity protection because the name includes 'Defender' and they think it covers all security, not realizing it focuses on cloud infrastructure rather than on-premises Active Directory.
✗Microsoft SentinelWrong answer — click to see why▾
Why this is wrong here
Microsoft Sentinel is a SIEM/SOAR platform that ingests logs and alerts but does not natively monitor domain controller traffic or detect Active Directory attacks like Golden Ticket or skeleton key. It relies on other solutions (e.g., Defender for Identity) for such detections.
★ When this WOULD be the correct answer
A company needs a cloud-native SIEM to centralize security logs from multiple sources (e.g., firewalls, servers, cloud apps) and automate incident response. The question would specify that the goal is log aggregation and orchestration, not direct AD attack detection.
Why candidates choose this
Candidates may confuse Sentinel as the solution because it integrates with many security tools and can ingest identity-related alerts, but they overlook that it does not perform the actual monitoring of domain controller traffic or entity behavior analysis itself.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Kerberos
Kerberos is a network authentication protocol that uses tickets and symmetric-key cryptography to verify the identity of users and services in a secure, non-repudiable way.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.