SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A security team needs to detect and investigate advanced attacks targeting on-premises Active Directory accounts, such as Pass-the-Hash (PtH) and Golden Ticket attacks. Which Microsoft security solution should they deploy?
⚠ Common exam trap
Many exam-takers confuse Microsoft Defender for Identity with Microsoft Sentinel or Defender for Endpoint, not realizing that only Defender for Identity provides dedicated, protocol-level detection for on-premises Active Directory attacks like PtH and Golden Ticket.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Identity
Microsoft Defender for Identity (MDI) is specifically designed to detect advanced attacks targeting on-premises Active Directory, such as Pass-the-Hash (PtH) and Golden Ticket attacks. It uses behavioral analytics and machine learning to monitor AD traffic, Kerberos authentication, and NTLM protocol anomalies, identifying lateral movement and privilege escalation attempts that characterize these attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps (MDCAS) functions as a Cloud Access Security Broker (CASB), primarily focused on discovering shadow IT, protecting sensitive data in cloud applications, and monitoring user activity across SaaS environments. While it enhances cloud security posture and provides visibility into cloud app usage, it does not possess specialized capabilities or detection logic for identifying advanced attacks directly targeting on-premises Active Directory infrastructure or credential theft within the local network. Its scope is cloud application governance, not on-premises identity protection.
When this WOULD be correct
A question asks: 'Which Microsoft solution should be used to discover and control the use of shadow IT cloud apps and protect cloud app data from threats?'
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Microsoft Defender for Endpoint (MDE) is an enterprise endpoint security platform that provides endpoint detection and response (EDR), next-generation antivirus, and automated investigation capabilities for devices. While crucial for protecting individual workstations and servers from malware and exploits, MDE's primary focus is on endpoint-level threats and activities, not the specialized monitoring of Active Directory domain controllers or the detection of network-based identity attacks like Pass-the-Hash or Golden Ticket, which require deep AD protocol understanding.
When this WOULD be correct
A question asking for a solution to detect and investigate advanced attacks on endpoints, such as fileless malware or ransomware on Windows devices, would make Microsoft Defender for Endpoint the correct answer.
- ✓
Microsoft Defender for Identity
Why this is correct
Microsoft Defender for Identity (MDI) is purpose-built to detect advanced threats targeting on-premises Active Directory and hybrid identity environments. It monitors domain controllers and network traffic for suspicious activities, leveraging behavioral analytics to identify credential theft, lateral movement, and sophisticated attacks like Pass-the-Hash or Golden Ticket. MDI provides specialized insights into identity-based threats, enabling rapid investigation and response to protect critical authentication infrastructure.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM/SOAR solution that can ingest security logs from various sources, but it does not have specialized, built-in detection logic for on-premises Active Directory attacks. Defender for Identity provides such specialized detections and can feed alerts to Sentinel.
When this WOULD be correct
A security team needs to centralize security event monitoring, correlate alerts from multiple sources (e.g., firewalls, endpoints, cloud apps), and orchestrate automated incident response across the enterprise. In that scenario, Microsoft Sentinel would be the correct choice.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Defender for IdentityCorrect answer▾
Why this is correct
Microsoft Defender for Identity (MDI) is purpose-built to detect advanced threats targeting on-premises Active Directory and hybrid identity environments. It monitors domain controllers and network traffic for suspicious activities, leveraging behavioral analytics to identify credential theft, lateral movement, and sophisticated attacks like Pass-the-Hash or Golden Ticket. MDI provides specialized insights into identity-based threats, enabling rapid investigation and response to protect critical authentication infrastructure.
✗Microsoft Defender for Cloud AppsWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Cloud Apps is a CASB focused on cloud application security, not on-premises Active Directory attack detection like PtH or Golden Ticket.
★ When this WOULD be the correct answer
A question asks: 'Which Microsoft solution should be used to discover and control the use of shadow IT cloud apps and protect cloud app data from threats?'
Why candidates choose this
Candidates may confuse cloud app security with identity security, assuming all advanced attacks are covered under a broad 'cloud security' umbrella.
✗Microsoft Defender for EndpointWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Endpoint focuses on endpoint devices (e.g., workstations, servers) and does not specialize in monitoring on-premises Active Directory for identity-based attacks like Pass-the-Hash or Golden Ticket.
★ When this WOULD be the correct answer
A question asking for a solution to detect and investigate advanced attacks on endpoints, such as fileless malware or ransomware on Windows devices, would make Microsoft Defender for Endpoint the correct answer.
Why candidates choose this
Candidates may confuse endpoint protection with identity protection, assuming that Defender for Endpoint covers all attack vectors including Active Directory, due to its broad 'Defender' branding.
✗Microsoft SentinelWrong answer — click to see why▾
Why this is wrong here
Microsoft Sentinel is a SIEM/SOAR solution that aggregates logs and generates alerts, but it does not natively detect advanced on-premises Active Directory attacks like Pass-the-Hash or Golden Ticket. It relies on data sources such as Defender for Identity to provide that detection capability.
★ When this WOULD be the correct answer
A security team needs to centralize security event monitoring, correlate alerts from multiple sources (e.g., firewalls, endpoints, cloud apps), and orchestrate automated incident response across the enterprise. In that scenario, Microsoft Sentinel would be the correct choice.
Why candidates choose this
Candidates may confuse Sentinel's broad security analytics and threat detection capabilities with the specialized identity-focused detection needed for on-premises AD attacks, assuming a SIEM can directly detect such attacks without dedicated identity sensors.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Golden ticket
A forged Kerberos authentication ticket that grants an attacker unrestricted domain admin access to all resources in a Windows Active Directory environment.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.