Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company uses Microsoft Defender for Cloud to secure its environment. Which TWO plans are available?

⚠ Common exam trap

Candidates often confuse Microsoft Sentinel and Microsoft Defender for Identity as being 'plans' within Defender for Cloud because they are part of the broader Microsoft security ecosystem and integrate with Defender for Cloud, but they are separate services with their own licensing and management interfaces.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Security Posture Management (CSPM)

Option A, Cloud Security Posture Management (CSPM), is correct because it is one of the Defender for Cloud plans, providing continuous assessment of misconfigurations and security posture across Azure, AWS, and GCP resources. Option B, Defender for Servers, is correct because it is a Defender for Cloud workload protection plan (offered in P1 and P2 tiers) that delivers threat detection, vulnerability assessment, and file integrity monitoring for Windows and Linux VMs. Option C, Microsoft Intune, is incorrect because it is a separate cloud-based endpoint management/MDM service for device and app management, not a Defender for Cloud plan. Option D, Microsoft Sentinel, is incorrect because it is a standalone cloud-native SIEM/SOAR solution that integrates with Defender for Cloud but is not itself one of its plans. Option E, Microsoft Defender for Identity, is incorrect because it is a distinct service for monitoring on-premises Active Directory signals to detect identity-based attacks, not a Defender for Cloud plan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cloud Security Posture Management (CSPM)

    Why this is correct

    Microsoft Defender for Cloud's Cloud Security Posture Management (CSPM) is a foundational capability that continuously assesses the security posture of your cloud resources across Azure, AWS, and GCP. It provides visibility into misconfigurations, offers actionable security recommendations, and helps ensure compliance with industry benchmarks and regulatory standards. This core functionality is essential for identifying and remediating potential vulnerabilities in your cloud environment.

  • ✓

    Defender for Servers

    Why this is correct

    Defender for Servers is an advanced plan within Microsoft Defender for Cloud, providing comprehensive threat protection and vulnerability management for your server workloads, whether they are in Azure, on-premises, or in other clouds. It includes capabilities like just-in-time (JIT) VM access, adaptive application controls, file integrity monitoring, and integration with Microsoft Defender for Endpoint for advanced endpoint detection and response (EDR). This specialized offering enhances the security of your critical server infrastructure against sophisticated attacks.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is primarily a cloud-based service focused on mobile device management (MDM) and mobile application management (MAM). Its core function is to manage and secure endpoints like mobile phones, tablets, and PCs, as well as the applications running on them, ensuring corporate data protection. While Intune contributes to overall enterprise security, it does not directly secure cloud infrastructure or provide the security posture management and threat protection for cloud resources that Microsoft Defender for Cloud offers.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It provides intelligent security analytics and threat intelligence across an entire enterprise, collecting data from various sources to detect, investigate, and respond to threats. While Sentinel can ingest security alerts from Defender for Cloud, it is a distinct, broader security operations platform, rather than an integrated component for securing specific cloud environments within Defender for Cloud itself.

  • ✗

    Microsoft Defender for Identity

    Why it's wrong here

    Microsoft Defender for Identity is a cloud-based security solution that leverages your on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization. It focuses specifically on protecting hybrid identity environments and detecting identity-based attacks. While crucial for overall security, it is a separate product within the Microsoft 365 Defender suite, distinct from Microsoft Defender for Cloud's primary role of securing cloud infrastructure and services.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.