SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which TWO of the following are capabilities of Microsoft Sentinel? (Choose two.)
⚠ Common exam trap
Candidates often confuse Microsoft Sentinel's ability to ingest and correlate EDR alerts with actually performing EDR functions, leading them to select 'Endpoint detection and response' as a Sentinel capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security information and event management (SIEM)
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) solution that aggregates log data from across an organization to detect, investigate, and respond to threats. It also provides Security Orchestration, Automation, and Response (SOAR) capabilities through built-in playbooks and automation rules, enabling automated incident response workflows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security information and event management (SIEM)
Why this is correct
Microsoft Sentinel is fundamentally a cloud-native Security Information and Event Management (SIEM) solution. It provides centralized security data collection from various sources, including Microsoft 365, Azure, on-premises systems, and other cloud providers, ingesting logs and alerts at scale. Sentinel then uses analytics, machine learning, and threat intelligence to detect, investigate, and respond to threats across an organization's digital estate, offering a comprehensive view of security posture.
- ✓
Security orchestration, automation, and response (SOAR)
Why this is correct
Microsoft Sentinel integrates robust Security Orchestration, Automation, and Response (SOAR) capabilities to streamline incident management. It leverages Azure Logic Apps as "playbooks" to automate repetitive security tasks, such as blocking malicious IPs, isolating compromised hosts, or enriching incident data. Automation rules further enable automatic responses to specific alerts, significantly reducing manual effort and accelerating threat mitigation.
- ✗
Endpoint detection and response (EDR)
Why it's wrong here
Endpoint Detection and Response (EDR) is not a native capability of Microsoft Sentinel itself. EDR focuses on monitoring and responding to threats specifically on endpoint devices like workstations and servers, a function primarily performed by Microsoft Defender for Endpoint. While Sentinel ingests EDR alerts and data from Defender for Endpoint for broader correlation and analysis, it does not perform the real-time endpoint monitoring, behavioral analysis, or direct remediation actions on the endpoint that characterize EDR solutions.
- ✗
Vulnerability scanning
Why it's wrong here
Vulnerability scanning, which involves identifying security weaknesses and misconfigurations in systems, applications, and networks, is not a core capability of Microsoft Sentinel. Sentinel's primary role is to aggregate and analyze security events and alerts, not to actively scan for vulnerabilities. This function is typically performed by dedicated vulnerability management solutions, such as the integrated vulnerability assessment tools within Microsoft Defender for Cloud or various third-party scanning products.
- ✗
Data classification and labeling
Why it's wrong here
Data classification and labeling, which involves identifying sensitive information and applying protective labels to it based on its sensitivity, is outside the scope of Microsoft Sentinel's core functions. Sentinel is designed for security operations and threat detection, not for managing data governance or information protection policies. These capabilities are primarily provided by Microsoft Purview Information Protection, which helps organizations discover, classify, and protect sensitive data across their digital estate.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
SOAR
SOAR (Security Orchestration, Automation, and Response) is a technology stack that helps security teams automate responses to threats by integrating various security tools and standardizing workflows.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.