Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A security team needs to detect and investigate advanced attacks targeting on-premises Active Directory accounts, such as Pass-the-Hash (PtH) and Golden Ticket attacks. Which Microsoft security solution should they deploy?

⚠ Common exam trap

Many exam-takers confuse Microsoft Defender for Identity with Microsoft Sentinel or Defender for Endpoint, not realizing that only Defender for Identity provides dedicated, protocol-level detection for on-premises Active Directory attacks like PtH and Golden Ticket.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Identity

Microsoft Defender for Identity (MDI) is specifically designed to detect advanced attacks targeting on-premises Active Directory, such as Pass-the-Hash (PtH) and Golden Ticket attacks. It uses behavioral analytics and machine learning to monitor AD traffic, Kerberos authentication, and NTLM protocol anomalies, identifying lateral movement and privilege escalation attempts that characterize these attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps (MDCAS) functions as a Cloud Access Security Broker (CASB), primarily focused on discovering shadow IT, protecting sensitive data in cloud applications, and monitoring user activity across SaaS environments. While it enhances cloud security posture and provides visibility into cloud app usage, it does not possess specialized capabilities or detection logic for identifying advanced attacks directly targeting on-premises Active Directory infrastructure or credential theft within the local network. Its scope is cloud application governance, not on-premises identity protection.

    When this WOULD be correct

    A question asks: 'Which Microsoft solution should be used to discover and control the use of shadow IT cloud apps and protect cloud app data from threats?'

  • Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint (MDE) is an enterprise endpoint security platform that provides endpoint detection and response (EDR), next-generation antivirus, and automated investigation capabilities for devices. While crucial for protecting individual workstations and servers from malware and exploits, MDE's primary focus is on endpoint-level threats and activities, not the specialized monitoring of Active Directory domain controllers or the detection of network-based identity attacks like Pass-the-Hash or Golden Ticket, which require deep AD protocol understanding.

    When this WOULD be correct

    A question asking for a solution to detect and investigate advanced attacks on endpoints, such as fileless malware or ransomware on Windows devices, would make Microsoft Defender for Endpoint the correct answer.

  • Microsoft Defender for Identity

    Why this is correct

    Microsoft Defender for Identity (MDI) is purpose-built to detect advanced threats targeting on-premises Active Directory and hybrid identity environments. It monitors domain controllers and network traffic for suspicious activities, leveraging behavioral analytics to identify credential theft, lateral movement, and sophisticated attacks like Pass-the-Hash or Golden Ticket. MDI provides specialized insights into identity-based threats, enabling rapid investigation and response to protect critical authentication infrastructure.

  • Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM/SOAR solution that can ingest security logs from various sources, but it does not have specialized, built-in detection logic for on-premises Active Directory attacks. Defender for Identity provides such specialized detections and can feed alerts to Sentinel.

    When this WOULD be correct

    A security team needs to centralize security event monitoring, correlate alerts from multiple sources (e.g., firewalls, endpoints, cloud apps), and orchestrate automated incident response across the enterprise. In that scenario, Microsoft Sentinel would be the correct choice.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft Defender for IdentityCorrect answer

Why this is correct

Microsoft Defender for Identity (MDI) is purpose-built to detect advanced threats targeting on-premises Active Directory and hybrid identity environments. It monitors domain controllers and network traffic for suspicious activities, leveraging behavioral analytics to identify credential theft, lateral movement, and sophisticated attacks like Pass-the-Hash or Golden Ticket. MDI provides specialized insights into identity-based threats, enabling rapid investigation and response to protect critical authentication infrastructure.

Microsoft Defender for Cloud AppsWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Cloud Apps is a CASB focused on cloud application security, not on-premises Active Directory attack detection like PtH or Golden Ticket.

★ When this WOULD be the correct answer

A question asks: 'Which Microsoft solution should be used to discover and control the use of shadow IT cloud apps and protect cloud app data from threats?'

Why candidates choose this

Candidates may confuse cloud app security with identity security, assuming all advanced attacks are covered under a broad 'cloud security' umbrella.

Microsoft Defender for EndpointWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Endpoint focuses on endpoint devices (e.g., workstations, servers) and does not specialize in monitoring on-premises Active Directory for identity-based attacks like Pass-the-Hash or Golden Ticket.

★ When this WOULD be the correct answer

A question asking for a solution to detect and investigate advanced attacks on endpoints, such as fileless malware or ransomware on Windows devices, would make Microsoft Defender for Endpoint the correct answer.

Why candidates choose this

Candidates may confuse endpoint protection with identity protection, assuming that Defender for Endpoint covers all attack vectors including Active Directory, due to its broad 'Defender' branding.

Microsoft SentinelWrong answer — click to see why

Why this is wrong here

Microsoft Sentinel is a SIEM/SOAR solution that aggregates logs and generates alerts, but it does not natively detect advanced on-premises Active Directory attacks like Pass-the-Hash or Golden Ticket. It relies on data sources such as Defender for Identity to provide that detection capability.

★ When this WOULD be the correct answer

A security team needs to centralize security event monitoring, correlate alerts from multiple sources (e.g., firewalls, endpoints, cloud apps), and orchestrate automated incident response across the enterprise. In that scenario, Microsoft Sentinel would be the correct choice.

Why candidates choose this

Candidates may confuse Sentinel's broad security analytics and threat detection capabilities with the specialized identity-focused detection needed for on-premises AD attacks, assuming a SIEM can directly detect such attacks without dedicated identity sensors.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.