SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which TWO of the following are capabilities of Microsoft Defender for Cloud?
⚠ Common exam trap
Many exam-takers confuse the security monitoring and management capabilities of different Microsoft security products, assuming Defender for Cloud does everything from SIEM to identity protection to mobile device management, when in reality it is focused on cloud security posture management (CSPM) and cloud workload protection (CWP).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable just-in-time access to virtual machines
Option A is correct because Microsoft Defender for Cloud provides just-in-time (JIT) VM access, which locks down inbound RDP/SSH ports and grants time-limited, request-based access to virtual machines, reducing exposure to brute-force attacks. Option D is correct because Defender for Cloud's core Secure Score capability continuously assesses cloud resources against security recommendations and benchmarks (e.g., Microsoft Cloud Security Benchmark) to measure and improve security posture. Option B does not belong because centralized multi-source security event log analysis is the role of Microsoft Sentinel (SIEM), not Defender for Cloud. Option C does not belong because monitoring domain controllers for malicious activity is handled by Microsoft Defender for Identity, a separate service. Option E does not belong because mobile device management and compliance enforcement are capabilities of Microsoft Intune, not Defender for Cloud.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable just-in-time access to virtual machines
Why this is correct
Microsoft Defender for Cloud offers just-in-time (JIT) virtual machine access as a core security capability. This feature significantly reduces the attack surface by locking down inbound traffic to your Azure VMs, only opening necessary ports for a limited, configurable time when a user explicitly requests access. This ephemeral access is granted only after a successful authentication and, optionally, multi-factor authentication, ensuring that VMs are exposed to the internet only when actively needed.
- ✗
Centralize security event log analysis from multiple sources
Why it's wrong here
Centralizing security event log analysis from diverse sources, including on-premises servers, cloud services, and network devices, is a primary function of Microsoft Sentinel. Sentinel operates as a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution, designed to ingest vast amounts of security data, detect threats using AI and machine learning, and automate responses. While Defender for Cloud provides security alerts, it does not offer the comprehensive, cross-source log aggregation and advanced analytics capabilities of a dedicated SIEM like Sentinel.
- ✗
Monitor domain controllers for malicious activity
Why it's wrong here
Monitoring domain controllers for malicious activity, such as suspicious authentication attempts, privilege escalation, or replication anomalies, is a specialized capability of Microsoft Defender for Identity. This solution focuses specifically on protecting hybrid identity environments by leveraging behavioral analytics and machine learning to detect advanced threats and compromised identities targeting Active Directory. Defender for Cloud, while protecting cloud workloads, does not provide the deep, identity-centric threat detection specific to domain controllers that Defender for Identity offers.
- ✓
Assess and improve the security posture of your cloud resources
Why this is correct
Microsoft Defender for Cloud continuously assesses and helps improve the security posture of your cloud resources across Azure, AWS, and GCP environments. It provides a Secure Score, which is a quantified measure of your security posture, along with actionable recommendations to remediate vulnerabilities and misconfigurations. This capability includes identifying security gaps, enforcing regulatory compliance standards, and offering a centralized view of security health, thereby proactively strengthening your overall cloud security.
- ✗
Manage mobile devices and enforce compliance policies
Why it's wrong here
Managing mobile devices and enforcing compliance policies, such as requiring device encryption, setting password complexity, or controlling application access, is a core function of Microsoft Intune. Intune is a cloud-based unified endpoint management (UEM) solution that enables organizations to manage endpoints like mobile phones, tablets, and laptops, and to deploy applications and enforce security policies across these devices. This is distinct from Defender for Cloud, which focuses on securing cloud infrastructure and workloads rather than endpoint management.
Go deeper
Related to this question
Learn chapter
Defender Vulnerability Management Basics
Key term
Defender for Identity
Defender for Identity is a cloud-based security solution that detects, investigates, and responds to advanced identity threats targeting on-premises Active Directory and cloud identities.
Key term
Event
An event is any identifiable occurrence or action in a computer system, network, or application that can be logged, monitored, or analyzed for security or operational purposes.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.