Courseiva
Question 477 of 1,250

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A security team is evaluating Microsoft security solutions to monitor user activities across multiple SaaS applications, including Salesforce and Dropbox, for signs of compromised accounts and data exfiltration. Which solution is specifically designed for this purpose?

⚠ Common exam trap

Test-takers frequently confuse Microsoft Sentinel (a SIEM) with a CASB, but Sentinel is a log aggregation and analysis platform, not a dedicated SaaS monitoring solution like Defender for Cloud Apps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides deep visibility, data classification, and threat detection across SaaS applications like Salesforce and Dropbox. It uses behavioral analytics and anomaly detection to identify compromised accounts and data exfiltration by monitoring user activities and applying policies such as activity policies and app governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Cloud Apps

    Why this is correct

    Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing comprehensive visibility, control, and threat protection for sanctioned and unsanctioned cloud applications. It directly monitors user activities within SaaS applications like Salesforce or Dropbox, detecting anomalous behavior, preventing data exfiltration, and enforcing compliance policies. This solution is purpose-built to address the unique security challenges posed by cloud application usage, offering real-time controls and deep insights into data movement and user interactions.

  • Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint is an Endpoint Detection and Response (EDR) solution focused on securing endpoint devices such as workstations, servers, and mobile devices. It provides advanced threat protection, post-breach detection, automated investigation, and response capabilities by collecting telemetry directly from the operating system and applications running on the device itself. It does not, however, provide direct monitoring of user activities or data flows within cloud-based SaaS applications, which operate independently of the endpoint's local environment.

    When this WOULD be correct

    A question asking for a solution to detect and respond to advanced threats on endpoints, such as malware, ransomware, or suspicious process behaviors on Windows or macOS devices, would make Microsoft Defender for Endpoint the correct answer.

  • Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution designed for enterprise-wide security operations. While Sentinel can ingest security logs and alerts from various sources, including SaaS applications (often via connectors or other Defender products), it is primarily an aggregation, analysis, and incident management platform. It does not inherently provide the real-time, granular monitoring, control, or shadow IT discovery capabilities specific to user activities within SaaS applications that a CASB offers.

    When this WOULD be correct

    A question asks: 'Which Microsoft solution provides a centralized security information and event management (SIEM) platform that can ingest logs from multiple sources, including on-premises and cloud, and uses advanced analytics to detect threats?' In that scenario, Microsoft Sentinel would be the correct answer.

  • Microsoft 365 Defender

    Why it's wrong here

    Microsoft 365 Defender is an Extended Detection and Response (XDR) suite that unifies protection across endpoints, identities, email, and cloud apps, providing coordinated defense. While it integrates the capabilities of Microsoft Defender for Cloud Apps, Defender for Endpoint, Defender for Identity, and Defender for Office 365, it is the overarching platform, not the specific component responsible for monitoring user activities within SaaS applications. The core functionality for SaaS app monitoring and protection is provided by its constituent service, Defender for Cloud Apps.

    When this WOULD be correct

    A question asks: 'Which Microsoft solution provides a unified incident response experience across endpoints, email, and identities, and correlates alerts from multiple security products into a single queue?' In that scenario, Microsoft 365 Defender would be the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft Defender for Cloud AppsCorrect answer

Why this is correct

Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing comprehensive visibility, control, and threat protection for sanctioned and unsanctioned cloud applications. It directly monitors user activities within SaaS applications like Salesforce or Dropbox, detecting anomalous behavior, preventing data exfiltration, and enforcing compliance policies. This solution is purpose-built to address the unique security challenges posed by cloud application usage, offering real-time controls and deep insights into data movement and user interactions.

Microsoft Defender for EndpointWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Endpoint focuses on endpoint devices (e.g., laptops, servers) and does not natively monitor user activities across SaaS applications like Salesforce and Dropbox for compromised accounts and data exfiltration.

★ When this WOULD be the correct answer

A question asking for a solution to detect and respond to advanced threats on endpoints, such as malware, ransomware, or suspicious process behaviors on Windows or macOS devices, would make Microsoft Defender for Endpoint the correct answer.

Why candidates choose this

Candidates may confuse 'endpoint' broadly with all user devices accessing SaaS apps, or assume Defender for Endpoint covers cloud app monitoring because it integrates with Microsoft 365 Defender.

Microsoft SentinelWrong answer — click to see why

Why this is wrong here

Microsoft Sentinel is a SIEM/SOAR solution for aggregating and analyzing security data from multiple sources, but it is not specifically designed to monitor user activities across SaaS applications like Salesforce and Dropbox for compromised accounts and data exfiltration; that is the role of Defender for Cloud Apps.

★ When this WOULD be the correct answer

A question asks: 'Which Microsoft solution provides a centralized security information and event management (SIEM) platform that can ingest logs from multiple sources, including on-premises and cloud, and uses advanced analytics to detect threats?' In that scenario, Microsoft Sentinel would be the correct answer.

Why candidates choose this

Candidates may think Sentinel can monitor SaaS apps because it can ingest logs from various sources, but they overlook that Defender for Cloud Apps is purpose-built for SaaS app security with features like app discovery and session monitoring.

Microsoft 365 DefenderWrong answer — click to see why

Why this is wrong here

Microsoft 365 Defender is a unified pre- and post-breach enterprise defense suite that protects across endpoints, identities, email, and applications, but it does not specialize in monitoring user activities across third-party SaaS apps like Salesforce and Dropbox for signs of compromised accounts and data exfiltration. That specific capability is provided by Microsoft Defender for Cloud Apps.

★ When this WOULD be the correct answer

A question asks: 'Which Microsoft solution provides a unified incident response experience across endpoints, email, and identities, and correlates alerts from multiple security products into a single queue?' In that scenario, Microsoft 365 Defender would be the correct answer.

Why candidates choose this

Candidates may confuse Microsoft 365 Defender as the overarching security suite and assume it includes all monitoring capabilities, not realizing that Defender for Cloud Apps is the dedicated solution for SaaS app monitoring and shadow IT discovery.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.