SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A security team needs to detect and investigate suspicious activities in their on-premises Active Directory environment, such as pass-the-hash attacks, Kerberoasting, and unusual service account behavior. They also want to integrate these alerts with Microsoft Defender for Cloud for a unified view across hybrid workloads. Which Microsoft security solution should they deploy on-premises?
⚠ Common exam trap
Watch out — candidates often confuse Microsoft Defender for Identity with Microsoft Defender for Endpoint, assuming endpoint protection covers AD attacks, but MDI is the only solution that specifically monitors Active Directory authentication and behavior on domain controllers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Identity
Microsoft Defender for Identity (MDI) is the correct solution because it is specifically designed to detect and investigate advanced threats in on-premises Active Directory environments, including pass-the-hash attacks, Kerberoasting, and anomalous service account behavior. It uses behavioral analytics and integrates directly with Microsoft Defender for Cloud to provide a unified view across hybrid workloads, enabling security teams to correlate on-premises AD signals with cloud alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Identity
Why this is correct
Microsoft Defender for Identity is purpose-built to protect hybrid identity environments by monitoring on-premises Active Directory (AD) domain controllers and AD FS servers. It leverages network traffic analysis and Windows event logs to detect sophisticated identity-based attacks, such as Pass-the-Hash, Pass-the-Ticket, Kerberoasting, and Golden Ticket attacks. By building behavioral profiles of users and entities, it identifies anomalous activities that indicate compromise, providing crucial insights into the identity attack kill chain.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 provides advanced protection against threats originating from email, Microsoft Teams, SharePoint Online, and OneDrive for Business. It includes capabilities like Safe Attachments, Safe Links, anti-phishing, and anti-spam policies to safeguard users from malicious content and sophisticated phishing campaigns. Its scope is exclusively focused on securing cloud-based productivity services, not the underlying on-premises Active Directory infrastructure or identity management.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), extending visibility and control over cloud applications and services. It helps organizations discover shadow IT, protect sensitive data across cloud apps, detect anomalous user behavior, and assess compliance risks. This solution specifically targets the security of SaaS applications and cloud services, offering no direct monitoring or protection for on-premises Active Directory environments.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Microsoft Defender for Endpoint delivers comprehensive endpoint detection and response (EDR) capabilities, focusing on threat prevention, post-breach detection, automated investigation, and response for devices. It monitors workstations, servers, and mobile devices for malicious activity, exploits, and vulnerabilities. While it can detect endpoint-level attacks that might eventually interact with Active Directory, its primary function is device security, not the direct analysis of Active Directory authentication traffic or domain controller logs for identity-specific threats.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Service account
A service account is a special type of account used by an application or a virtual machine, rather than a human user, to authenticate and interact with cloud services and APIs securely.
Key term
Defender for Identity
Defender for Identity is a cloud-based security solution that detects, investigates, and responds to advanced identity threats targeting on-premises Active Directory and cloud identities.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.