Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company wants to detect and respond to advanced attacks targeting their on-premises Active Directory infrastructure, such as Kerberos Golden Ticket attacks, pass-the-hash, and brute-force attempts. The solution should integrate with Microsoft Sentinel and Microsoft 365 Defender for cross-domain investigations. Which Microsoft security solution should they deploy?

⚠ Common exam trap

Test-takers frequently confuse Defender for Identity with Defender for Endpoint, assuming endpoint protection covers identity attacks, but MDI is the only solution that directly monitors Active Directory authentication protocols and domain controller traffic for advanced on-premises identity threats.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Identity

Microsoft Defender for Identity (MDI) is specifically designed to protect on-premises Active Directory by monitoring for advanced attacks like Kerberos Golden Ticket, pass-the-hash, and brute-force attempts. It integrates natively with Microsoft Sentinel and Microsoft 365 Defender to enable cross-domain investigations, correlating identity signals with endpoint and cloud data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint is an enterprise endpoint security platform that focuses on protecting devices like workstations, servers, and mobile devices from cyber threats. It provides Endpoint Detection and Response (EDR) capabilities, vulnerability management, and automated investigation and remediation directly on the endpoint operating system. While crucial for overall security, its primary scope is the security posture and activities occurring *on* the individual devices, rather than monitoring the Active Directory infrastructure itself for directory-specific attacks.

    When this WOULD be correct

    A company wants to detect and respond to advanced attacks on endpoints, such as fileless malware, ransomware, or post-breach activities on workstations and servers, and needs integration with Microsoft Sentinel and Microsoft 365 Defender for cross-domain investigations.

  • Microsoft Defender for Identity

    Why this is correct

    Microsoft Defender for Identity is purpose-built to monitor on-premises Active Directory (AD) and hybrid environments for advanced threats. It deploys sensors directly on domain controllers and AD FS servers to analyze network traffic and Windows events, detecting suspicious user and entity behavior, reconnaissance activities, lateral movement paths, and privilege escalation techniques like Pass-the-Hash or Golden Ticket attacks. This specialized focus on identity-based threats within the AD infrastructure makes it the ideal solution for protecting against attacks targeting an organization's core directory services.

  • Microsoft Defender for Office 365

    Why it's wrong here

    Microsoft Defender for Office 365 is a cloud-based email and collaboration security service designed to protect against advanced threats like phishing, business email compromise (BEC), malware, and zero-day attacks across Office 365 services. It provides advanced anti-phishing, safe attachments, safe links, and protection for SharePoint, OneDrive, and Microsoft Teams. Its specialized capabilities are tailored to secure communication and collaboration platforms, not to monitor or protect the underlying on-premises Active Directory infrastructure from identity-based attacks.

    When this WOULD be correct

    A question asking for a solution to protect against phishing, malware, and advanced threats in email and Office 365 apps, with integration into Microsoft Sentinel and Microsoft 365 Defender for cross-domain investigations.

  • Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing visibility, control, and threat protection for cloud applications and services. It helps organizations discover shadow IT, protect sensitive data in cloud apps, and identify anomalous behavior or compliance violations across SaaS, PaaS, and IaaS environments. Its focus is exclusively on securing cloud application usage and data, making it unsuitable for detecting advanced attacks specifically targeting an on-premises Active Directory infrastructure.

    When this WOULD be correct

    A company wants to discover and control the use of shadow IT cloud apps, enforce data loss prevention policies for SaaS applications, and detect anomalous behavior in cloud app usage. The solution must integrate with Microsoft Sentinel for investigation.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft Defender for IdentityCorrect answer

Why this is correct

Microsoft Defender for Identity is purpose-built to monitor on-premises Active Directory (AD) and hybrid environments for advanced threats. It deploys sensors directly on domain controllers and AD FS servers to analyze network traffic and Windows events, detecting suspicious user and entity behavior, reconnaissance activities, lateral movement paths, and privilege escalation techniques like Pass-the-Hash or Golden Ticket attacks. This specialized focus on identity-based threats within the AD infrastructure makes it the ideal solution for protecting against attacks targeting an organization's core directory services.

Microsoft Defender for EndpointWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Endpoint focuses on endpoint devices (e.g., workstations, servers) and does not specifically monitor or protect on-premises Active Directory infrastructure against attacks like Kerberos Golden Ticket or pass-the-hash.

★ When this WOULD be the correct answer

A company wants to detect and respond to advanced attacks on endpoints, such as fileless malware, ransomware, or post-breach activities on workstations and servers, and needs integration with Microsoft Sentinel and Microsoft 365 Defender for cross-domain investigations.

Why candidates choose this

Candidates may assume that Defender for Endpoint covers all security needs, including Active Directory, because it is a comprehensive endpoint protection solution, but it lacks the specific AD security capabilities of Defender for Identity.

Microsoft Defender for Office 365Wrong answer — click to see why

Why this is wrong here

Microsoft Defender for Office 365 protects email and collaboration tools, not on-premises Active Directory. It cannot detect Kerberos Golden Ticket attacks or pass-the-hash targeting AD.

★ When this WOULD be the correct answer

A question asking for a solution to protect against phishing, malware, and advanced threats in email and Office 365 apps, with integration into Microsoft Sentinel and Microsoft 365 Defender for cross-domain investigations.

Why candidates choose this

Candidates may confuse the 'Defender' branding and assume all Defender products cover similar threats, or they may think Office 365 includes AD protection due to Azure AD Connect.

Microsoft Defender for Cloud AppsWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that protects cloud applications, not on-premises Active Directory. It cannot detect Kerberos Golden Ticket attacks or pass-the-hash on on-premises AD.

★ When this WOULD be the correct answer

A company wants to discover and control the use of shadow IT cloud apps, enforce data loss prevention policies for SaaS applications, and detect anomalous behavior in cloud app usage. The solution must integrate with Microsoft Sentinel for investigation.

Why candidates choose this

Candidates may think Defender for Cloud Apps covers all security aspects including on-premises, or they confuse its identity protection capabilities with those of Defender for Identity.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Go deeper

Related to this question

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.