SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company uses Microsoft 365 and Microsoft Azure. The security team wants a single portal that provides a unified view of alerts and incidents from their endpoints, email, and cloud applications to accelerate threat investigation and response. Which Microsoft security solution should they use?
⚠ Common exam trap
Test-takers frequently confuse Microsoft 365 Defender portal (a unified incident view for Microsoft 365 security products) with Microsoft Sentinel (a SIEM), not realizing that Sentinel requires additional setup and is not the out-of-the-box single portal for Microsoft's own security alerts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft 365 Defender portal
Microsoft 365 Defender portal (now part of the Microsoft 365 Defender unified security operations platform) is designed to aggregate alerts and incidents from endpoints (Microsoft Defender for Endpoint), email (Microsoft Defender for Office 365), and cloud applications (Microsoft Defender for Cloud Apps) into a single queue. This unified view enables security teams to triage and investigate threats across these domains without switching between separate consoles, directly accelerating response times.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft 365 Defender portal
Why this is correct
The Microsoft 365 Defender portal is the unified security operations center for Microsoft 365 services. It consolidates alerts, incidents, and automated investigation and response capabilities from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Microsoft Defender for Cloud Apps. This centralized experience provides a comprehensive view of threats across the entire Microsoft 365 ecosystem, enabling security teams to efficiently investigate and remediate multi-stage attacks.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is primarily focused on cloud security posture management (CSPM) and cloud workload protection (CWP) for Azure, multi-cloud environments (AWS, GCP), and hybrid infrastructure. While it secures virtual machines, containers, and databases, it does not provide the integrated, unified incident management experience for Microsoft 365 specific services such as email (Exchange Online) or user endpoints (Defender for Endpoint) that Microsoft 365 Defender offers.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It is designed to ingest security data from a vast array of sources, including Microsoft 365 Defender, Azure, other clouds, and on-premises systems, for centralized logging, threat detection, and automated response. However, it serves as an aggregation and correlation platform, not the dedicated, native portal for managing and responding to incidents generated directly by the integrated components of Microsoft 365 Defender.
- ✗
Microsoft Purview Compliance Manager
Why it's wrong here
Microsoft Purview Compliance Manager is a tool within the Microsoft Purview suite designed to help organizations manage their compliance posture against various regulatory standards and industry frameworks. It provides a dashboard to assess compliance risk, track progress on improvement actions, and generate reports. This service is focused on governance, risk, and compliance (GRC) activities and does not offer capabilities for real-time threat detection, incident investigation, or security response, which are core functions of security operations centers.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email and collaboration security service that protects organizations against malicious threats like phishing, malware, and spam in email messages and Office 365 apps.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.