Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Which TWO of the following are capabilities of Microsoft Defender for Cloud?

⚠ Common exam trap

Many exam-takers confuse the security monitoring and management capabilities of different Microsoft security products, assuming Defender for Cloud does everything from SIEM to identity protection to mobile device management, when in reality it is focused on cloud security posture management (CSPM) and cloud workload protection (CWP).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable just-in-time access to virtual machines

Option A is correct because Microsoft Defender for Cloud provides just-in-time (JIT) VM access, which locks down inbound RDP/SSH ports and grants time-limited, request-based access to virtual machines, reducing exposure to brute-force attacks. Option D is correct because Defender for Cloud's core Secure Score capability continuously assesses cloud resources against security recommendations and benchmarks (e.g., Microsoft Cloud Security Benchmark) to measure and improve security posture. Option B does not belong because centralized multi-source security event log analysis is the role of Microsoft Sentinel (SIEM), not Defender for Cloud. Option C does not belong because monitoring domain controllers for malicious activity is handled by Microsoft Defender for Identity, a separate service. Option E does not belong because mobile device management and compliance enforcement are capabilities of Microsoft Intune, not Defender for Cloud.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable just-in-time access to virtual machines

    Why this is correct

    Microsoft Defender for Cloud offers just-in-time (JIT) virtual machine access as a core security capability. This feature significantly reduces the attack surface by locking down inbound traffic to your Azure VMs, only opening necessary ports for a limited, configurable time when a user explicitly requests access. This ephemeral access is granted only after a successful authentication and, optionally, multi-factor authentication, ensuring that VMs are exposed to the internet only when actively needed.

  • ✗

    Centralize security event log analysis from multiple sources

    Why it's wrong here

    Centralizing security event log analysis from diverse sources, including on-premises servers, cloud services, and network devices, is a primary function of Microsoft Sentinel. Sentinel operates as a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution, designed to ingest vast amounts of security data, detect threats using AI and machine learning, and automate responses. While Defender for Cloud provides security alerts, it does not offer the comprehensive, cross-source log aggregation and advanced analytics capabilities of a dedicated SIEM like Sentinel.

  • ✗

    Monitor domain controllers for malicious activity

    Why it's wrong here

    Monitoring domain controllers for malicious activity, such as suspicious authentication attempts, privilege escalation, or replication anomalies, is a specialized capability of Microsoft Defender for Identity. This solution focuses specifically on protecting hybrid identity environments by leveraging behavioral analytics and machine learning to detect advanced threats and compromised identities targeting Active Directory. Defender for Cloud, while protecting cloud workloads, does not provide the deep, identity-centric threat detection specific to domain controllers that Defender for Identity offers.

  • ✓

    Assess and improve the security posture of your cloud resources

    Why this is correct

    Microsoft Defender for Cloud continuously assesses and helps improve the security posture of your cloud resources across Azure, AWS, and GCP environments. It provides a Secure Score, which is a quantified measure of your security posture, along with actionable recommendations to remediate vulnerabilities and misconfigurations. This capability includes identifying security gaps, enforcing regulatory compliance standards, and offering a centralized view of security health, thereby proactively strengthening your overall cloud security.

  • ✗

    Manage mobile devices and enforce compliance policies

    Why it's wrong here

    Managing mobile devices and enforcing compliance policies, such as requiring device encryption, setting password complexity, or controlling application access, is a core function of Microsoft Intune. Intune is a cloud-based unified endpoint management (UEM) solution that enables organizations to manage endpoints like mobile phones, tablets, and laptops, and to deploy applications and enforce security policies across these devices. This is distinct from Defender for Cloud, which focuses on securing cloud infrastructure and workloads rather than endpoint management.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.