SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company's security operations team needs to centralize security log collection from multiple sources including on-premises firewalls, AWS CloudTrail, and Azure Active Directory sign-in logs. They want to use built-in analytics to detect threats across all data sources and create automated response playbooks, such as isolating a compromised user account when a specific attack pattern is detected. Which Microsoft security solution should they deploy?
⚠ Common exam trap
Watch out — candidates often confuse Microsoft Sentinel (a SIEM for multi-source log ingestion and automated response) with Microsoft 365 Defender (an XDR for Microsoft ecosystem threats), failing to recognize that only Sentinel can ingest third-party logs like on-premises firewalls and AWS CloudTrail for centralized threat detection and playbook automation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel
Microsoft Sentinel is the correct choice because it is a cloud-native SIEM (Security Information and Event Management) solution that ingests logs from diverse sources (on-premises firewalls via Syslog, AWS CloudTrail via REST API, and Azure AD via diagnostic settings) and provides built-in analytics rules to detect threats across all data. It also integrates with Azure Logic Apps to create automated playbooks (e.g., isolating a compromised user account) triggered by detected attack patterns, fulfilling the requirement for centralized log collection and automated response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud serves as a Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP). It provides security recommendations, vulnerability management, and threat protection specifically for cloud resources across Azure, AWS, and GCP environments. Its focus is on hardening and protecting individual cloud workloads and services, rather than acting as a centralized repository for all security logs from diverse on-premises and cloud sources for SIEM analysis.
When this WOULD be correct
A company wants to assess and improve the security posture of their Azure, AWS, and GCP workloads, get recommendations for hardening, and protect against cloud-specific threats like misconfigurations and vulnerabilities. They need a solution that provides unified visibility and threat protection across cloud environments.
- ✓
Microsoft Sentinel
Why this is correct
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It is explicitly designed for centralizing security data from virtually any source, including Microsoft services, on-premises infrastructure, and other cloud providers. This enables comprehensive threat detection through AI and machine learning, alongside automated responses to security incidents across the entire enterprise.
- ✗
Microsoft 365 Defender
Why it's wrong here
Microsoft 365 Defender is an Extended Detection and Response (XDR) solution that unifies protection across specific Microsoft 365 services. It integrates signals from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps to provide a cohesive view of threats within the Microsoft 365 ecosystem. However, it is not designed to ingest security logs from third-party systems, on-premises infrastructure, or other non-Microsoft cloud providers, which is essential for a truly centralized, enterprise-wide security operations platform.
When this WOULD be correct
A company wants to unify detection and response across Microsoft 365 services (Exchange, SharePoint, Teams, endpoints) and use built-in automated investigation and remediation for threats like phishing or malware, without needing to ingest non-Microsoft logs or create custom playbooks.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing deep visibility and control over cloud applications. Its primary role involves discovering shadow IT, enforcing data loss prevention policies, and monitoring user activities within sanctioned and unsanctioned cloud services. While crucial for cloud app security, it does not offer the broad log ingestion and centralized threat correlation capabilities required for a full-fledged SIEM solution across an entire IT estate.
When this WOULD be correct
A company wants to discover and control the use of unsanctioned cloud apps (shadow IT), enforce data loss prevention policies for cloud applications, and get visibility into user activities across SaaS apps like Office 365, Salesforce, or AWS.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft SentinelCorrect answer▾
Why this is correct
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It is explicitly designed for centralizing security data from virtually any source, including Microsoft services, on-premises infrastructure, and other cloud providers. This enables comprehensive threat detection through AI and machine learning, alongside automated responses to security incidents across the entire enterprise.
✗Microsoft Defender for CloudWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that focuses on securing cloud resources, not on centralizing security logs from multiple sources (including on-premises) with built-in SIEM analytics and automated response playbooks.
★ When this WOULD be the correct answer
A company wants to assess and improve the security posture of their Azure, AWS, and GCP workloads, get recommendations for hardening, and protect against cloud-specific threats like misconfigurations and vulnerabilities. They need a solution that provides unified visibility and threat protection across cloud environments.
Why candidates choose this
Candidates may confuse Defender for Cloud's multi-cloud support and threat detection capabilities with the centralized log collection and SIEM/SOAR features of Sentinel, especially since both involve security monitoring and analytics.
✗Microsoft 365 DefenderWrong answer — click to see why▾
Why this is wrong here
Microsoft 365 Defender is designed to protect Microsoft 365 workloads (e.g., email, endpoints, identities) and does not natively ingest third-party logs like AWS CloudTrail or on-premises firewalls, nor does it provide centralized SIEM capabilities for multi-source log collection and custom automated playbooks.
★ When this WOULD be the correct answer
A company wants to unify detection and response across Microsoft 365 services (Exchange, SharePoint, Teams, endpoints) and use built-in automated investigation and remediation for threats like phishing or malware, without needing to ingest non-Microsoft logs or create custom playbooks.
Why candidates choose this
Candidates may confuse Microsoft 365 Defender's security analytics and automation features with Sentinel's SIEM capabilities, or assume that 'Defender' products cover all security needs, overlooking the requirement for multi-source log ingestion and custom playbooks.
✗Microsoft Defender for Cloud AppsWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) focused on shadow IT discovery and controlling access to cloud apps, not a centralized SIEM/SOAR for multi-source log collection and automated threat response.
★ When this WOULD be the correct answer
A company wants to discover and control the use of unsanctioned cloud apps (shadow IT), enforce data loss prevention policies for cloud applications, and get visibility into user activities across SaaS apps like Office 365, Salesforce, or AWS.
Why candidates choose this
Candidates may confuse Defender for Cloud Apps with a general security analytics tool because its name includes 'Defender' and it deals with cloud logs, but it lacks the centralized SIEM and SOAR capabilities of Sentinel.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft Sentinel
Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration automation and response (SOAR) service that helps organizations detect, investigate, and respond to cyber threats across their entire digital estate.
Key term
Syslog
Syslog is a standard protocol used to send and store log messages from network devices and servers to a central logging server for monitoring and troubleshooting.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.