SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A global enterprise has a hybrid environment that includes on-premises Active Directory, Azure resources, Amazon Web Services (AWS), and Google Cloud Platform (GCP). The security team needs a single solution to collect security logs from all these sources, detect threats using advanced analytics and threat intelligence, and automate incident response via playbooks. They already have Microsoft Defender for Cloud protecting their Azure workloads. Which Microsoft security solution should they add to meet these requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel
Microsoft Sentinel is a cloud-native SIEM and SOAR solution that ingests logs from a wide range of sources, including on-premises, Azure, AWS, and GCP. It provides advanced analytics, threat detection, and automated response through playbooks. Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection solution; while it does collect some logs and can send alerts to Sentinel, it does not provide the full SIEM/SOAR capabilities needed for multi-cloud aggregation and automation beyond Azure. Microsoft Defender for Identity focuses on on-premises AD threats but not multi-cloud. Microsoft Cloud App Security is a CASB for SaaS apps, not a SIEM for infrastructure logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Sentinel
Why this is correct
Microsoft Sentinel is a scalable, cloud-native SIEM and SOAR that can ingest logs from on-premises, Azure, AWS, GCP, and many other sources. It provides threat detection and automated response via playbooks, making it the correct solution for the described need.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud provides Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) across Azure, hybrid, and multi-cloud environments (AWS, GCP). While it offers integrated security for workloads, including threat protection and vulnerability management, it is not designed as a comprehensive Security Information and Event Management (SIEM) solution. It lacks the broad log aggregation from diverse multi-cloud and on-premises sources for all security events, and it does not provide the extensive Security Orchestration, Automation, and Response (SOAR) capabilities that a full SIEM like Sentinel offers.
- ✗
Microsoft Defender for Identity
Why it's wrong here
Microsoft Defender for Identity is a specialized security solution focused on protecting on-premises Active Directory (AD) environments. It monitors user behavior and detects identity-based threats such as lateral movement, privilege escalation, and compromised credentials within the AD domain. However, it does not ingest security logs from multi-cloud platforms like AWS or GCP, nor does it provide the comprehensive SIEM analytics and broad SOAR automation capabilities necessary for a global enterprise managing a hybrid and multi-cloud security operations center.
- ✗
Microsoft Cloud App Security
Why it's wrong here
Microsoft Cloud App Security is a CASB that focuses on SaaS applications (e.g., Salesforce, Box). It does not provide infrastructure log collection from clouds like AWS or GCP, nor does it serve as a full SIEM for all security events.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
SSE
SSE (Security Service Edge) is a cloud-centric security framework that converges web, cloud, and network security into a single edge service.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.