SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company wants to detect and respond to advanced attacks targeting their on-premises Active Directory infrastructure, such as Kerberos Golden Ticket attacks, pass-the-hash, and brute-force attempts. The solution should integrate with Microsoft Sentinel and Microsoft 365 Defender for cross-domain investigations. Which Microsoft security solution should they deploy?
⚠ Common exam trap
Test-takers frequently confuse Defender for Identity with Defender for Endpoint, assuming endpoint protection covers identity attacks, but MDI is the only solution that directly monitors Active Directory authentication protocols and domain controller traffic for advanced on-premises identity threats.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Identity
Microsoft Defender for Identity (MDI) is specifically designed to protect on-premises Active Directory by monitoring for advanced attacks like Kerberos Golden Ticket, pass-the-hash, and brute-force attempts. It integrates natively with Microsoft Sentinel and Microsoft 365 Defender to enable cross-domain investigations, correlating identity signals with endpoint and cloud data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Microsoft Defender for Endpoint is an enterprise endpoint security platform that focuses on protecting devices like workstations, servers, and mobile devices from cyber threats. It provides Endpoint Detection and Response (EDR) capabilities, vulnerability management, and automated investigation and remediation directly on the endpoint operating system. While crucial for overall security, its primary scope is the security posture and activities occurring *on* the individual devices, rather than monitoring the Active Directory infrastructure itself for directory-specific attacks.
When this WOULD be correct
A company wants to detect and respond to advanced attacks on endpoints, such as fileless malware, ransomware, or post-breach activities on workstations and servers, and needs integration with Microsoft Sentinel and Microsoft 365 Defender for cross-domain investigations.
- ✓
Microsoft Defender for Identity
Why this is correct
Microsoft Defender for Identity is purpose-built to monitor on-premises Active Directory (AD) and hybrid environments for advanced threats. It deploys sensors directly on domain controllers and AD FS servers to analyze network traffic and Windows events, detecting suspicious user and entity behavior, reconnaissance activities, lateral movement paths, and privilege escalation techniques like Pass-the-Hash or Golden Ticket attacks. This specialized focus on identity-based threats within the AD infrastructure makes it the ideal solution for protecting against attacks targeting an organization's core directory services.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 is a cloud-based email and collaboration security service designed to protect against advanced threats like phishing, business email compromise (BEC), malware, and zero-day attacks across Office 365 services. It provides advanced anti-phishing, safe attachments, safe links, and protection for SharePoint, OneDrive, and Microsoft Teams. Its specialized capabilities are tailored to secure communication and collaboration platforms, not to monitor or protect the underlying on-premises Active Directory infrastructure from identity-based attacks.
When this WOULD be correct
A question asking for a solution to protect against phishing, malware, and advanced threats in email and Office 365 apps, with integration into Microsoft Sentinel and Microsoft 365 Defender for cross-domain investigations.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing visibility, control, and threat protection for cloud applications and services. It helps organizations discover shadow IT, protect sensitive data in cloud apps, and identify anomalous behavior or compliance violations across SaaS, PaaS, and IaaS environments. Its focus is exclusively on securing cloud application usage and data, making it unsuitable for detecting advanced attacks specifically targeting an on-premises Active Directory infrastructure.
When this WOULD be correct
A company wants to discover and control the use of shadow IT cloud apps, enforce data loss prevention policies for SaaS applications, and detect anomalous behavior in cloud app usage. The solution must integrate with Microsoft Sentinel for investigation.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Defender for IdentityCorrect answer▾
Why this is correct
Microsoft Defender for Identity is purpose-built to monitor on-premises Active Directory (AD) and hybrid environments for advanced threats. It deploys sensors directly on domain controllers and AD FS servers to analyze network traffic and Windows events, detecting suspicious user and entity behavior, reconnaissance activities, lateral movement paths, and privilege escalation techniques like Pass-the-Hash or Golden Ticket attacks. This specialized focus on identity-based threats within the AD infrastructure makes it the ideal solution for protecting against attacks targeting an organization's core directory services.
✗Microsoft Defender for EndpointWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Endpoint focuses on endpoint devices (e.g., workstations, servers) and does not specifically monitor or protect on-premises Active Directory infrastructure against attacks like Kerberos Golden Ticket or pass-the-hash.
★ When this WOULD be the correct answer
A company wants to detect and respond to advanced attacks on endpoints, such as fileless malware, ransomware, or post-breach activities on workstations and servers, and needs integration with Microsoft Sentinel and Microsoft 365 Defender for cross-domain investigations.
Why candidates choose this
Candidates may assume that Defender for Endpoint covers all security needs, including Active Directory, because it is a comprehensive endpoint protection solution, but it lacks the specific AD security capabilities of Defender for Identity.
✗Microsoft Defender for Office 365Wrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Office 365 protects email and collaboration tools, not on-premises Active Directory. It cannot detect Kerberos Golden Ticket attacks or pass-the-hash targeting AD.
★ When this WOULD be the correct answer
A question asking for a solution to protect against phishing, malware, and advanced threats in email and Office 365 apps, with integration into Microsoft Sentinel and Microsoft 365 Defender for cross-domain investigations.
Why candidates choose this
Candidates may confuse the 'Defender' branding and assume all Defender products cover similar threats, or they may think Office 365 includes AD protection due to Azure AD Connect.
✗Microsoft Defender for Cloud AppsWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that protects cloud applications, not on-premises Active Directory. It cannot detect Kerberos Golden Ticket attacks or pass-the-hash on on-premises AD.
★ When this WOULD be the correct answer
A company wants to discover and control the use of shadow IT cloud apps, enforce data loss prevention policies for SaaS applications, and detect anomalous behavior in cloud app usage. The solution must integrate with Microsoft Sentinel for investigation.
Why candidates choose this
Candidates may think Defender for Cloud Apps covers all security aspects including on-premises, or they confuse its identity protection capabilities with those of Defender for Identity.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft Sentinel
Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration automation and response (SOAR) service that helps organizations detect, investigate, and respond to cyber threats across their entire digital estate.
Key term
Kerberos
Kerberos is a network authentication protocol that uses tickets and symmetric-key cryptography to verify the identity of users and services in a secure, non-repudiable way.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.