Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company uses Microsoft Purview to map their data estate. They need to classify data stored in Azure SQL Database and Amazon S3. What should they use?

⚠ Common exam trap

Watch out — candidates often confuse Microsoft Purview Data Map with Microsoft Defender for Cloud, mistakenly thinking that Defender for Cloud's 'data classification' feature (which only applies to Azure SQL and Azure Storage) can also scan Amazon S3, but it cannot—only Purview Data Map supports multi-cloud data sources like AWS S3.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Purview Data Map

Microsoft Purview Data Map is the correct choice because it provides automated data discovery, classification, and lineage across hybrid and multi-cloud environments, including Azure SQL Database and Amazon S3. It uses built-in scanners and classifiers to scan structured and unstructured data sources, mapping sensitive data types such as PII or financial information. This directly fulfills the requirement to classify data across both Azure and AWS platforms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Intune

    Why it's wrong here

    Microsoft Intune is a cloud-based service focused on endpoint management, enabling organizations to manage mobile devices, desktop computers, and applications. Its primary function is to secure and deploy corporate resources to devices, enforce compliance policies, and manage application lifecycle, rather than mapping or classifying data content across an entire data estate.

  • Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a scalable, cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It aggregates security data from various sources, detects threats using AI and machine learning, and facilitates incident response. Sentinel's purpose is security operations and threat intelligence, not the discovery, cataloging, or classification of data assets for governance.

  • Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud provides comprehensive cloud security posture management (CSPM) and cloud workload protection (CWP) across hybrid and multi-cloud environments. It continuously assesses the security state of cloud resources, identifies vulnerabilities, and offers recommendations to strengthen security posture. While crucial for security, it does not perform the detailed data scanning, classification, and lineage tracking required to map a data estate for governance purposes.

  • Microsoft Purview Data Map

    Why this is correct

    The Microsoft Purview Data Map is the foundational component of Microsoft Purview, designed to automatically discover, catalog, and classify data assets across an organization's entire data estate, including on-premises, multi-cloud, and SaaS sources. It creates a unified metadata repository, providing a holistic view of data locations, types, and relationships. This capability is essential for understanding data landscapes, enabling data governance, compliance, and risk management initiatives.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.