Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company uses Microsoft 365 and Microsoft Azure. The security team wants a single portal that provides a unified view of alerts and incidents from their endpoints, email, and cloud applications to accelerate threat investigation and response. Which Microsoft security solution should they use?

⚠ Common exam trap

Test-takers frequently confuse Microsoft 365 Defender portal (a unified incident view for Microsoft 365 security products) with Microsoft Sentinel (a SIEM), not realizing that Sentinel requires additional setup and is not the out-of-the-box single portal for Microsoft's own security alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft 365 Defender portal

Microsoft 365 Defender portal (now part of the Microsoft 365 Defender unified security operations platform) is designed to aggregate alerts and incidents from endpoints (Microsoft Defender for Endpoint), email (Microsoft Defender for Office 365), and cloud applications (Microsoft Defender for Cloud Apps) into a single queue. This unified view enables security teams to triage and investigate threats across these domains without switching between separate consoles, directly accelerating response times.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft 365 Defender portal

    Why this is correct

    The Microsoft 365 Defender portal is the unified security operations center for Microsoft 365 services. It consolidates alerts, incidents, and automated investigation and response capabilities from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Microsoft Defender for Cloud Apps. This centralized experience provides a comprehensive view of threats across the entire Microsoft 365 ecosystem, enabling security teams to efficiently investigate and remediate multi-stage attacks.

  • Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud is primarily focused on cloud security posture management (CSPM) and cloud workload protection (CWP) for Azure, multi-cloud environments (AWS, GCP), and hybrid infrastructure. While it secures virtual machines, containers, and databases, it does not provide the integrated, unified incident management experience for Microsoft 365 specific services such as email (Exchange Online) or user endpoints (Defender for Endpoint) that Microsoft 365 Defender offers.

  • Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It is designed to ingest security data from a vast array of sources, including Microsoft 365 Defender, Azure, other clouds, and on-premises systems, for centralized logging, threat detection, and automated response. However, it serves as an aggregation and correlation platform, not the dedicated, native portal for managing and responding to incidents generated directly by the integrated components of Microsoft 365 Defender.

  • Microsoft Purview Compliance Manager

    Why it's wrong here

    Microsoft Purview Compliance Manager is a tool within the Microsoft Purview suite designed to help organizations manage their compliance posture against various regulatory standards and industry frameworks. It provides a dashboard to assess compliance risk, track progress on improvement actions, and generate reports. This service is focused on governance, risk, and compliance (GRC) activities and does not offer capabilities for real-time threat detection, incident investigation, or security response, which are core functions of security operations centers.

Go deeper

Related to this question

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.