SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which THREE of the following are capabilities of Microsoft Sentinel? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security information and event management (SIEM)
Correct: A (SIEM), B (UEBA), D (SOAR). C is not a Sentinel capability; it is a feature of Microsoft Intune. E is a feature of Microsoft Purview.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security information and event management (SIEM)
Why this is correct
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) solution. It provides centralized security data collection from various sources, including users, applications, servers, and network devices, across an organization's entire digital estate. Sentinel then uses advanced analytics and threat intelligence to detect, investigate, and respond to threats by correlating these events in real-time. This capability is fundamental to its role in modern security operations.
- ✓
User and entity behavior analytics (UEBA)
Why this is correct
Microsoft Sentinel incorporates User and Entity Behavior Analytics (UEBA) capabilities to identify anomalous activities that deviate from established baselines for users, hosts, and applications. By continuously monitoring and profiling behavior patterns, Sentinel's UEBA engine can detect subtle indicators of compromise, such as unusual login times, access to sensitive data, or atypical resource usage, which might signal insider threats or compromised accounts. This proactive analysis helps in uncovering sophisticated threats that traditional signature-based detection might miss.
- ✗
Mobile device management
Why it's wrong here
Mobile Device Management (MDM) is a capability primarily offered by Microsoft Intune, which is part of Microsoft Endpoint Manager. MDM focuses on securing, deploying, and managing corporate and personal mobile devices, including configuration, application deployment, and data protection policies. While Sentinel might ingest logs from devices managed by Intune, it does not directly perform the device management functions itself, making it distinct from Sentinel's SIEM/SOAR focus.
- ✓
Security orchestration, automation, and response (SOAR)
Why this is correct
Microsoft Sentinel provides robust Security Orchestration, Automation, and Response (SOAR) capabilities through its integration with Azure Logic Apps, enabling the creation of automated playbooks. These playbooks can automatically execute predefined actions in response to security incidents, such as isolating compromised hosts, blocking malicious IP addresses, or notifying security teams. This automation significantly reduces manual effort and accelerates incident response times, improving overall security posture.
- ✗
Data loss prevention
Why it's wrong here
Data Loss Prevention (DLP) is a specialized capability primarily provided by Microsoft Purview, which focuses on identifying, monitoring, and protecting sensitive information across an organization's digital estate. DLP policies prevent unauthorized sharing, transfer, or use of sensitive data by enforcing rules on content, context, and user actions. While Sentinel might alert on events related to DLP policy violations, it does not directly implement or enforce the data protection policies itself, distinguishing it from a dedicated DLP solution.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
SIEM
SIEM (Security Information and Event Management) is a system that collects and analyzes log data from across an IT environment to detect and respond to security threats in real time.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are capabilities of Microsoft Sentinel? (Choose two.)
hard- ✓ A.Security information and event management (SIEM)
- ✓ B.Security orchestration, automation, and response (SOAR)
- C.Endpoint detection and response (EDR)
- D.Vulnerability scanning
- E.Data classification and labeling
Why A: Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) solution that aggregates log data from across an organization to detect, investigate, and respond to threats. It also provides Security Orchestration, Automation, and Response (SOAR) capabilities through built-in playbooks and automation rules, enabling automated incident response workflows.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.