Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A security operations center (SOC) team needs to ingest security logs from on-premises servers, Azure virtual machines, and SaaS applications like Salesforce. They want a cloud-native solution that uses machine learning to detect threats, provides a unified query language for hunting, and supports automated incident response through playbooks. Which Microsoft solution should they deploy?

⚠ Common exam trap

It's easy for candidates to confuse Microsoft Defender for Cloud (a CSPM tool) with a SIEM, or assume Microsoft 365 Defender can ingest third-party SaaS logs, but only Microsoft Sentinel provides a cloud-native SIEM with unified log ingestion, ML threat detection, and automated playbook response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Sentinel

Microsoft Sentinel is the correct choice because it is a cloud-native SIEM (Security Information and Event Management) solution that ingests logs from on-premises servers, Azure VMs, and SaaS applications like Salesforce. It uses built-in machine learning to detect threats, offers the Kusto Query Language (KQL) for unified hunting, and supports automated incident response via playbooks built on Azure Logic Apps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud primarily provides cloud security posture management (CSPM) and workload protection for Azure, on-premises, and other clouds, but it is not a full SIEM for log ingestion and hunting across diverse sources.

    When this WOULD be correct

    A question asking for a solution to assess and improve the security posture of Azure and hybrid workloads, detect misconfigurations, and provide just-in-time VM access. For example: 'Which Microsoft service provides continuous assessment of security configurations and recommendations for Azure resources?'

  • Microsoft Sentinel

    Why this is correct

    Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It is specifically designed for a Security Operations Center (SOC) team to ingest security logs from a vast array of sources, including Microsoft services, third-party applications, on-premises infrastructure, and other cloud providers. Sentinel centralizes this data for advanced threat detection using machine learning, behavioral analytics, and threat intelligence, enabling comprehensive security monitoring, hunting, and automated response playbooks.

  • Microsoft 365 Defender

    Why it's wrong here

    Microsoft 365 Defender is an integrated XDR solution focused on protecting the Microsoft 365 environment (email, endpoints, identity, cloud apps), not designed for ingesting logs from third-party SaaS or on-premises servers into a unified SIEM.

    When this WOULD be correct

    A question asking for a solution to detect, investigate, and respond to threats across Microsoft 365 services (Exchange, SharePoint, Teams) and endpoints, with integrated threat signals from Microsoft Defender products, and requiring automated response capabilities within the Microsoft 365 ecosystem.

  • Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint (MDE) is an enterprise endpoint detection and response (EDR) platform focused on protecting devices such as workstations, servers, and mobile devices. While MDE provides robust capabilities for detecting, investigating, and responding to threats on endpoints, it is not designed to function as a centralized Security Information and Event Management (SIEM) system. It primarily collects telemetry from endpoints and does not aggregate security logs from diverse sources like network devices, cloud applications, or other infrastructure components into a unified platform for broad security analytics and correlation.

    When this WOULD be correct

    A question that asks for a solution to protect endpoints (e.g., Windows, macOS, Linux devices) from advanced threats, with capabilities for endpoint detection and response, automated investigation, and threat hunting specifically on devices, and where the environment does not require multi-source log ingestion or SIEM functionality.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft SentinelCorrect answer

Why this is correct

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It is specifically designed for a Security Operations Center (SOC) team to ingest security logs from a vast array of sources, including Microsoft services, third-party applications, on-premises infrastructure, and other cloud providers. Sentinel centralizes this data for advanced threat detection using machine learning, behavioral analytics, and threat intelligence, enabling comprehensive security monitoring, hunting, and automated response playbooks.

Microsoft Defender for CloudWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform, not a SIEM/SOAR solution. It lacks a unified query language (KQL) for hunting across diverse data sources and does not natively support automated incident response playbooks like Sentinel.

★ When this WOULD be the correct answer

A question asking for a solution to assess and improve the security posture of Azure and hybrid workloads, detect misconfigurations, and provide just-in-time VM access. For example: 'Which Microsoft service provides continuous assessment of security configurations and recommendations for Azure resources?'

Why candidates choose this

Candidates may confuse Defender for Cloud's threat detection capabilities (e.g., Azure Defender) with a full SIEM, or assume its integration with Azure covers all log sources, overlooking the need for a unified query language and playbook automation.

Microsoft 365 DefenderWrong answer — click to see why

Why this is wrong here

Microsoft 365 Defender is designed to protect Microsoft 365 workloads (e.g., email, endpoints, identities) and does not natively ingest logs from on-premises servers, Azure VMs, or third-party SaaS like Salesforce, nor does it provide a unified query language (KQL) or playbook-based automated incident response.

★ When this WOULD be the correct answer

A question asking for a solution to detect, investigate, and respond to threats across Microsoft 365 services (Exchange, SharePoint, Teams) and endpoints, with integrated threat signals from Microsoft Defender products, and requiring automated response capabilities within the Microsoft 365 ecosystem.

Why candidates choose this

Candidates may confuse Microsoft 365 Defender as a comprehensive security solution for all environments, overlooking its focus on Microsoft 365 workloads and lack of support for third-party SaaS and on-premises log ingestion.

Microsoft Defender for EndpointWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR) for devices, not on ingesting logs from diverse sources like on-premises servers, Azure VMs, and SaaS apps, nor does it provide a unified query language (KQL) for hunting across those sources or support automated incident response playbooks.

★ When this WOULD be the correct answer

A question that asks for a solution to protect endpoints (e.g., Windows, macOS, Linux devices) from advanced threats, with capabilities for endpoint detection and response, automated investigation, and threat hunting specifically on devices, and where the environment does not require multi-source log ingestion or SIEM functionality.

Why candidates choose this

Candidates may confuse Defender for Endpoint's threat detection and automated response features with Sentinel's broader SIEM capabilities, or assume that 'Defender' products all provide similar log ingestion and hunting across multiple sources.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.