SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A multinational company uses a hybrid infrastructure with on-premises Active Directory and Azure resources. They have deployed Microsoft Defender for Cloud to protect their Azure workloads. They now want to extend threat detection to their on-premises Active Directory by collecting security events from domain controllers to detect attacks like Golden Ticket, DCSync, and malicious Kerberos activity. The solution should integrate with Microsoft Sentinel for automated response. Which security solution should they deploy on the on-premises domain controllers?
⚠ Common exam trap
Watch out — candidates often confuse Microsoft Defender for Cloud (a CSPM/CWPP tool) with Microsoft Defender for Identity (an AD-focused identity threat detection tool), because both names include 'Defender' and both can integrate with Sentinel, but only MDI monitors on-premises Active Directory authentication events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Identity
Microsoft Defender for Identity (MDI) is the correct solution because it is specifically designed to monitor on-premises Active Directory signals, including security events from domain controllers, to detect advanced identity-based attacks such as Golden Ticket, DCSync, and malicious Kerberos activity. MDI integrates natively with Microsoft Sentinel to enable automated response workflows, fulfilling the requirement for extending threat detection to on-premises AD.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud primarily offers Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) for multi-cloud environments, including Azure, AWS, and GCP. While it can extend some protection to on-premises servers via Azure Arc, its core capabilities are not designed for the specialized, deep analysis of Active Directory authentication protocols and event logs required to detect sophisticated attacks like Golden Ticket. It focuses on broader security posture and threat protection for cloud-native and hybrid workloads, rather than specific AD attack vectors.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Microsoft Defender for Endpoint is an Endpoint Detection and Response (EDR) solution focused on protecting individual devices, such as workstations and servers, from various threats. It monitors process execution, file system changes, network connections, and memory for malicious activity on the endpoint itself. However, it lacks the specialized visibility into Active Directory replication, Kerberos authentication traffic, and specific domain controller event patterns necessary to identify advanced AD-centric attacks like Golden Ticket, which exploit the directory service's trust model.
- ✓
Microsoft Defender for Identity
Why this is correct
Microsoft Defender for Identity is purpose-built to detect advanced threats targeting on-premises Active Directory environments by analyzing network traffic and Windows events from domain controllers. It deploys lightweight sensors directly on domain controllers or uses port mirroring to gain deep visibility into authentication protocols like Kerberos and NTLM. This specialized analysis allows it to identify suspicious user behavior, privilege escalation attempts, and specific attack patterns, such as Golden Ticket, Pass-the-Hash, and DCShadow, providing crucial security alerts for AD compromise. Its focus is precisely on the unique attack surface presented by Active Directory.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel functions as a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platform. Its primary role is to aggregate, correlate, and analyze security data and alerts from various sources, including other Microsoft security solutions like Defender for Identity, as well as third-party systems. While Sentinel is invaluable for centralized monitoring and incident response, it does not act as the primary sensor or detection engine for specialized on-premises Active Directory threats; instead, it ingests and enriches the detections generated by dedicated tools like Defender for Identity.
Visual reference
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.