Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A security team needs to detect and investigate suspicious activities in their on-premises Active Directory environment, such as pass-the-hash attacks, Kerberoasting, and unusual service account behavior. They also want to integrate these alerts with Microsoft Defender for Cloud for a unified view across hybrid workloads. Which Microsoft security solution should they deploy on-premises?

⚠ Common exam trap

Watch out — candidates often confuse Microsoft Defender for Identity with Microsoft Defender for Endpoint, assuming endpoint protection covers AD attacks, but MDI is the only solution that specifically monitors Active Directory authentication and behavior on domain controllers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Identity

Microsoft Defender for Identity (MDI) is the correct solution because it is specifically designed to detect and investigate advanced threats in on-premises Active Directory environments, including pass-the-hash attacks, Kerberoasting, and anomalous service account behavior. It uses behavioral analytics and integrates directly with Microsoft Defender for Cloud to provide a unified view across hybrid workloads, enabling security teams to correlate on-premises AD signals with cloud alerts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Identity

    Why this is correct

    Microsoft Defender for Identity is purpose-built to protect hybrid identity environments by monitoring on-premises Active Directory (AD) domain controllers and AD FS servers. It leverages network traffic analysis and Windows event logs to detect sophisticated identity-based attacks, such as Pass-the-Hash, Pass-the-Ticket, Kerberoasting, and Golden Ticket attacks. By building behavioral profiles of users and entities, it identifies anomalous activities that indicate compromise, providing crucial insights into the identity attack kill chain.

  • Microsoft Defender for Office 365

    Why it's wrong here

    Microsoft Defender for Office 365 provides advanced protection against threats originating from email, Microsoft Teams, SharePoint Online, and OneDrive for Business. It includes capabilities like Safe Attachments, Safe Links, anti-phishing, and anti-spam policies to safeguard users from malicious content and sophisticated phishing campaigns. Its scope is exclusively focused on securing cloud-based productivity services, not the underlying on-premises Active Directory infrastructure or identity management.

  • Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), extending visibility and control over cloud applications and services. It helps organizations discover shadow IT, protect sensitive data across cloud apps, detect anomalous user behavior, and assess compliance risks. This solution specifically targets the security of SaaS applications and cloud services, offering no direct monitoring or protection for on-premises Active Directory environments.

  • Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint delivers comprehensive endpoint detection and response (EDR) capabilities, focusing on threat prevention, post-breach detection, automated investigation, and response for devices. It monitors workstations, servers, and mobile devices for malicious activity, exploits, and vulnerabilities. While it can detect endpoint-level attacks that might eventually interact with Active Directory, its primary function is device security, not the direct analysis of Active Directory authentication traffic or domain controller logs for identity-specific threats.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.