Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Which TWO of the following are capabilities of Microsoft Sentinel? (Choose two.)

⚠ Common exam trap

Candidates often confuse Microsoft Sentinel's ability to ingest and correlate EDR alerts with actually performing EDR functions, leading them to select 'Endpoint detection and response' as a Sentinel capability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Security information and event management (SIEM)

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) solution that aggregates log data from across an organization to detect, investigate, and respond to threats. It also provides Security Orchestration, Automation, and Response (SOAR) capabilities through built-in playbooks and automation rules, enabling automated incident response workflows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Security information and event management (SIEM)

    Why this is correct

    Microsoft Sentinel is fundamentally a cloud-native Security Information and Event Management (SIEM) solution. It provides centralized security data collection from various sources, including Microsoft 365, Azure, on-premises systems, and other cloud providers, ingesting logs and alerts at scale. Sentinel then uses analytics, machine learning, and threat intelligence to detect, investigate, and respond to threats across an organization's digital estate, offering a comprehensive view of security posture.

  • Security orchestration, automation, and response (SOAR)

    Why this is correct

    Microsoft Sentinel integrates robust Security Orchestration, Automation, and Response (SOAR) capabilities to streamline incident management. It leverages Azure Logic Apps as "playbooks" to automate repetitive security tasks, such as blocking malicious IPs, isolating compromised hosts, or enriching incident data. Automation rules further enable automatic responses to specific alerts, significantly reducing manual effort and accelerating threat mitigation.

  • Endpoint detection and response (EDR)

    Why it's wrong here

    Endpoint Detection and Response (EDR) is not a native capability of Microsoft Sentinel itself. EDR focuses on monitoring and responding to threats specifically on endpoint devices like workstations and servers, a function primarily performed by Microsoft Defender for Endpoint. While Sentinel ingests EDR alerts and data from Defender for Endpoint for broader correlation and analysis, it does not perform the real-time endpoint monitoring, behavioral analysis, or direct remediation actions on the endpoint that characterize EDR solutions.

  • Vulnerability scanning

    Why it's wrong here

    Vulnerability scanning, which involves identifying security weaknesses and misconfigurations in systems, applications, and networks, is not a core capability of Microsoft Sentinel. Sentinel's primary role is to aggregate and analyze security events and alerts, not to actively scan for vulnerabilities. This function is typically performed by dedicated vulnerability management solutions, such as the integrated vulnerability assessment tools within Microsoft Defender for Cloud or various third-party scanning products.

  • Data classification and labeling

    Why it's wrong here

    Data classification and labeling, which involves identifying sensitive information and applying protective labels to it based on its sensitivity, is outside the scope of Microsoft Sentinel's core functions. Sentinel is designed for security operations and threat detection, not for managing data governance or information protection policies. These capabilities are primarily provided by Microsoft Purview Information Protection, which helps organizations discover, classify, and protect sensitive data across their digital estate.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.