Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Which TWO of the following are features of Microsoft Sentinel? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse Microsoft Sentinel's SIEM and SOAR capabilities with other Microsoft security products like Microsoft Defender for Endpoint (EDR) or Microsoft Purview (data classification), leading them to select options D or E instead of the correct SIEM and SOAR features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Security information and event management (SIEM)

Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) solution that collects security data from across an organization, providing threat detection, investigation, and response. It also includes SOAR (Security Orchestration, Automation, and Response) capabilities through playbooks and automation rules, enabling automated incident response. These two features are core to Sentinel's functionality.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Identity governance and administration

    Why it's wrong here

    Identity governance and administration is a core function of Microsoft Entra ID, not Microsoft Sentinel. This service focuses on managing digital identities, controlling access to resources, and ensuring compliance through features like access reviews, entitlement management, and Privileged Identity Management (PIM). While Sentinel can ingest logs related to identity activities, it does not directly perform identity lifecycle management or access policy enforcement.

  • Security information and event management (SIEM)

    Why this is correct

    Microsoft Sentinel's SIEM capabilities involve collecting security data at scale from diverse sources across an organization's entire digital estate. It then uses built-in analytics, machine learning, and threat intelligence to detect, investigate, and prioritize security threats. This centralized log management and threat detection are fundamental to its role as a modern cloud-native SIEM.

  • Security orchestration, automation, and response (SOAR)

    Why this is correct

    Sentinel extends its capabilities beyond detection by offering robust Security Orchestration, Automation, and Response (SOAR) functionalities. It leverages Azure Logic Apps to create automated playbooks that can execute predefined actions in response to detected threats. These playbooks enable rapid incident containment, enrichment, and remediation, significantly reducing manual effort and response times for security operations teams.

  • Endpoint detection and response (EDR)

    Why it's wrong here

    Endpoint Detection and Response (EDR) is a specialized capability primarily provided by Microsoft Defender for Endpoint. EDR solutions continuously monitor endpoint activity for malicious behavior, provide deep visibility into attacks, and enable automated or manual response actions directly on devices. While Sentinel can ingest EDR alerts and raw data for broader correlation, it does not perform the direct endpoint monitoring and response functions itself.

  • Data classification and labeling

    Why it's wrong here

    Data classification and labeling are integral components of Microsoft Purview Information Protection and Data Loss Prevention (DLP) solutions. These features enable organizations to identify, classify, and apply sensitivity labels to sensitive data across various locations, enforcing protection policies like encryption or access restrictions. Microsoft Sentinel focuses on security operations and threat detection, not the intrinsic classification or protection of data content.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.