SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company wants to collect security logs from on-premises servers, cloud applications, and network devices into a central repository, and then use advanced analytics detect threats and automate incident response. Which Microsoft security solution should they deploy?
⚠ Common exam trap
Many exam-takers confuse Microsoft Sentinel (a SIEM/SOAR) with Microsoft Defender for Cloud (a CSPM/CWPP), thinking both do log collection and threat detection, but only Sentinel provides a unified SIEM repository with advanced analytics and automated response across hybrid and multi-cloud sources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration Automated Response (SOAR) solution. It collects security logs from diverse sources like on-premises servers, cloud apps, and network devices into a central Log Analytics workspace, then uses built-in analytics and machine learning to detect threats and automate incident response via playbooks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Sentinel
Why this is correct
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It is explicitly designed to ingest security logs from diverse sources, including on-premises servers, network devices, and cloud services, through various data connectors like the Log Analytics agent. This centralized collection is fundamental for comprehensive threat detection, investigation, and automated response across hybrid environments.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud primarily functions as a Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP), focusing on securing Azure, multi-cloud, and hybrid cloud workloads. While it can monitor some on-premises server security configurations and vulnerabilities via Azure Arc, its core purpose is not broad, centralized SIEM log collection and analysis from diverse on-premises sources for general threat hunting and incident response.
- ✗
Microsoft 365 Defender
Why it's wrong here
Microsoft 365 Defender is an Extended Detection and Response (XDR) solution that unifies protection across specific Microsoft 365 components like endpoints, identities, email, and cloud apps. While it collects rich security signals from these integrated sources, it is not a general-purpose SIEM platform designed to ingest arbitrary security logs from all types of on-premises servers and network devices for broad security analytics and correlation.
- ✗
Azure Firewall
Why it's wrong here
Azure Firewall is a cloud-native, intelligent network firewall security service that provides threat protection for Azure Virtual Network resources. Its primary function involves filtering network traffic based on rules, providing threat intelligence-based filtering, and centralizing network security policies. It does not possess capabilities to collect security logs from on-premises servers for SIEM purposes, nor does it offer log analysis, threat detection, or incident response functionalities.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Microsoft Sentinel
Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration automation and response (SOAR) service that helps organizations detect, investigate, and respond to cyber threats across their entire digital estate.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.