SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A security operations center uses Microsoft Sentinel to detect and respond to threats across a hybrid environment. They need to understand the core capabilities of Sentinel. Which two capabilities are provided by Microsoft Sentinel? (Choose two.)
⚠ Common exam trap
The trap here is attributing endpoint or email security features to Microsoft Sentinel, which is a SIEM/SOAR platform rather than a configuration or email security tool.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use built-in machine learning analytics to detect previously unseen threats.
Microsoft Sentinel is a cloud-native SIEM and SOAR solution. Its core capabilities include ingesting security data from diverse sources across cloud and on-premises, and applying advanced analytics and machine learning to detect threats. Automated email attachment remediation is specific to Defender for Office 365, conditional access is an Entra ID feature, and baseline deployment is an Intune function, so they are not Sentinel capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Provide automated investigation and remediation of email attachments.
Why it's wrong here
Automated investigation and remediation of email attachments is a capability of Microsoft Defender for Office 365, not Microsoft Sentinel. Sentinel focuses on security orchestration, automation, and response (SOAR) through playbooks, but it does not natively perform email attachment detonation or remediation. That specific function belongs to the email security service.
- ✓
Use built-in machine learning analytics to detect previously unseen threats.
Why this is correct
Microsoft Sentinel applies built-in machine learning analytics and fusion detection to identify anomalous behavior and multi-stage attacks that may not be caught by static rules. This aligns with the SOC's need to detect advanced threats across hybrid resources. The analytics engine correlates alerts from various sources to surface high-fidelity incidents.
- ✓
Collect security data from users, devices, applications, and infrastructure across cloud and on-premises.
Why this is correct
Microsoft Sentinel includes data connectors that ingest logs from sources like Azure Activity, Microsoft 365, AWS, and on-premises syslog. This centralized data collection is fundamental to its SIEM function, enabling correlation and analysis across the entire estate. It directly supports the scenario's need to detect threats in a hybrid environment by providing comprehensive visibility.
- ✗
Manage and deploy security baselines to Windows devices.
Why it's wrong here
Managing security baselines for Windows devices is handled by Microsoft Intune or Microsoft Endpoint Manager. Sentinel does not deploy configurations or baselines to endpoints; it focuses on collecting and analyzing security data. While it can monitor compliance, it is not a device management tool. This option describes endpoint management, not SIEM/SOAR.
- ✗
Enforce conditional access policies for user sign-ins.
Why it's wrong here
Enforcing conditional access policies is a function of Microsoft Entra ID, not Microsoft Sentinel. Conditional access evaluates signals like user, device, and location to grant or block access. Sentinel can ingest sign-in logs and trigger playbooks, but it does not directly enforce access controls. This distractor confuses identity and access management with SIEM capabilities.
Go deeper
Related to this question
Learn chapter
Cloud App Governance and App Consent
Key term
SOAR
SOAR (Security Orchestration, Automation, and Response) is a technology stack that helps security teams automate responses to threats by integrating various security tools and standardizing workflows.
Key term
Baseline
A baseline is a documented starting point for the normal performance and behavior of a system, network, or component, used to detect changes and troubleshoot issues.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.