Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A security operations center uses Microsoft Sentinel to detect and respond to threats across a hybrid environment. They need to understand the core capabilities of Sentinel. Which two capabilities are provided by Microsoft Sentinel? (Choose two.)

⚠ Common exam trap

The trap here is attributing endpoint or email security features to Microsoft Sentinel, which is a SIEM/SOAR platform rather than a configuration or email security tool.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use built-in machine learning analytics to detect previously unseen threats.

Microsoft Sentinel is a cloud-native SIEM and SOAR solution. Its core capabilities include ingesting security data from diverse sources across cloud and on-premises, and applying advanced analytics and machine learning to detect threats. Automated email attachment remediation is specific to Defender for Office 365, conditional access is an Entra ID feature, and baseline deployment is an Intune function, so they are not Sentinel capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Provide automated investigation and remediation of email attachments.

    Why it's wrong here

    Automated investigation and remediation of email attachments is a capability of Microsoft Defender for Office 365, not Microsoft Sentinel. Sentinel focuses on security orchestration, automation, and response (SOAR) through playbooks, but it does not natively perform email attachment detonation or remediation. That specific function belongs to the email security service.

  • ✓

    Use built-in machine learning analytics to detect previously unseen threats.

    Why this is correct

    Microsoft Sentinel applies built-in machine learning analytics and fusion detection to identify anomalous behavior and multi-stage attacks that may not be caught by static rules. This aligns with the SOC's need to detect advanced threats across hybrid resources. The analytics engine correlates alerts from various sources to surface high-fidelity incidents.

  • ✓

    Collect security data from users, devices, applications, and infrastructure across cloud and on-premises.

    Why this is correct

    Microsoft Sentinel includes data connectors that ingest logs from sources like Azure Activity, Microsoft 365, AWS, and on-premises syslog. This centralized data collection is fundamental to its SIEM function, enabling correlation and analysis across the entire estate. It directly supports the scenario's need to detect threats in a hybrid environment by providing comprehensive visibility.

  • ✗

    Manage and deploy security baselines to Windows devices.

    Why it's wrong here

    Managing security baselines for Windows devices is handled by Microsoft Intune or Microsoft Endpoint Manager. Sentinel does not deploy configurations or baselines to endpoints; it focuses on collecting and analyzing security data. While it can monitor compliance, it is not a device management tool. This option describes endpoint management, not SIEM/SOAR.

  • ✗

    Enforce conditional access policies for user sign-ins.

    Why it's wrong here

    Enforcing conditional access policies is a function of Microsoft Entra ID, not Microsoft Sentinel. Conditional access evaluates signals like user, device, and location to grant or block access. Sentinel can ingest sign-in logs and trigger playbooks, but it does not directly enforce access controls. This distractor confuses identity and access management with SIEM capabilities.

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.