Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company uses Microsoft Defender for Cloud to protect its Azure and on-premises workloads. The security team wants to receive alerts when suspicious activities occur, such as a possible brute-force attack on a virtual machine. Which component of Defender for Cloud generates these security alerts?

⚠ Common exam trap

The trap here is mixing up posture management features like secure score with threat detection plans that actually generate alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Servers

Microsoft Defender for Servers is the correct answer because it is the Defender for Cloud plan that delivers threat detection for servers, including behavioral analytics that identify brute-force attacks and generate alerts. Secure score and regulatory compliance are posture management features, while Defender for Cloud Apps is a separate CASB product, so they do not produce the required security alerts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Defender for Servers

    Why this is correct

    Microsoft Defender for Servers is a plan within Microsoft Defender for Cloud that provides threat detection and advanced protection for Windows and Linux servers, including Azure VMs and on-premises machines. It analyzes signals like login events and process behavior to detect brute-force attacks and other suspicious activities, generating security alerts in Defender for Cloud.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Defender for Cloud Apps is a separate product focused on cloud access security broker (CASB) functionality, such as discovering shadow IT and controlling SaaS app usage. It is not the component within Defender for Cloud that generates alerts for Azure VM threats. The question asks about alerts from Defender for Cloud, not the standalone Cloud Apps service.

  • ✗

    Regulatory compliance dashboard

    Why it's wrong here

    The regulatory compliance dashboard in Defender for Cloud assesses workloads against standards like ISO 27001 and PCI DSS. It shows compliance states and recommendations but does not detect or alert on runtime threats such as brute-force attacks. It is a compliance assessment tool, not a threat detection engine.

  • ✗

    Secure score

    Why it's wrong here

    Secure score in Defender for Cloud provides a measurement of the security posture based on recommendations and controls. It does not generate real-time alerts for suspicious activities; instead, it helps prioritize improvements. It is a posture management metric, not a threat detection mechanism, so it cannot alert on brute-force attempts.

Go deeper

Related to this question

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.