SC-900 Questions 21-30: Microsoft Security Solutions

0
0

Focus keyphrase: SC-900 practice questions

Use these SC-900 practice questions to review Microsoft security solutions for the Microsoft Security, Compliance, and Identity Fundamentals exam. This set focuses on Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Cloud, endpoint protection, cloud app security, DDoS protection, and security posture recommendations.

These are original certification-style questions based on public Microsoft exam objectives and official documentation. They are written to feel exam-like without copying, paraphrasing, or reconstructing real exam-dump content.

SC-900Questions 21-30Microsoft security solutionsDefender + Sentinel
Where this fits in the series: This post continues the SC-900 practice path after SC-900 Questions 1-10: Identity, Security, and Compliance Fundamentals and SC-900 Questions 11-20: Microsoft Entra Identity and Access Management, both of which are in the human review queue. Questions 21-30 move from identity into Microsoft security products and common exam decision points.

SC-900 Questions 21-30: Microsoft security solutions

For each question, choose the best answer, then review the explanation and distractor analysis. SC-900 is a fundamentals exam, so expect product-selection questions: the key is knowing which Microsoft security service matches a scenario.

Exam tip: Watch the words SIEM/SOAR, endpoint, cloud workload, SaaS app discovery, and unified incidents. Those phrases usually point to different Microsoft security products.
Domain: Describe the capabilities of Microsoft security solutions

Question 21: Unified incidents across Microsoft security products

Scenario: A security operations team wants one place to investigate incidents that include signals from endpoints, email, identities, and cloud apps. The team wants correlated incidents rather than reviewing each workload in a completely separate portal.

Choose one answer.

  1. Microsoft Purview eDiscovery
  2. Microsoft Defender XDR
  3. Azure Policy
  4. Microsoft Entra Connect Sync

Correct answer: B — Microsoft Defender XDR

Explanation: Microsoft Defender XDR provides extended detection and response across Microsoft security workloads. It correlates alerts into incidents across areas such as endpoints, identities, email, collaboration, and cloud apps so analysts can investigate attacks in a unified experience.

Why the other options are wrong

  • A. Microsoft Purview eDiscovery is used for legal and investigation workflows around content discovery, not XDR incident correlation.
  • C. Azure Policy evaluates and enforces Azure resource compliance rules; it is not a security operations incident console.
  • D. Microsoft Entra Connect Sync synchronizes identities between on-premises Active Directory and Microsoft Entra ID.

Official reference: What is Microsoft Defender XDR?

Domain: Describe the capabilities of Microsoft security solutions

Question 22: Endpoint detection and response

Scenario: A company wants to protect Windows, macOS, Linux, iOS, and Android devices. Security analysts need endpoint detection and response capabilities, threat and vulnerability management, attack surface reduction, and automated investigation.

Choose one answer.

  1. Microsoft Defender for Cloud Apps
  2. Microsoft Sentinel
  3. Microsoft Defender for Endpoint
  4. Azure Bastion

Correct answer: C — Microsoft Defender for Endpoint

Explanation: Microsoft Defender for Endpoint is Microsoft’s endpoint security platform. It provides endpoint detection and response, next-generation protection, attack surface reduction, threat and vulnerability management, and automated investigation and remediation.

Why the other options are wrong

  • A. Defender for Cloud Apps focuses on cloud app discovery, SaaS security posture, app governance, and session controls.
  • B. Microsoft Sentinel is a cloud-native SIEM and SOAR platform. It can ingest endpoint data, but it is not the endpoint protection agent/platform itself.
  • D. Azure Bastion provides secure RDP/SSH access to Azure virtual machines without exposing public management ports.

Official reference: Microsoft Defender for Endpoint documentation

Domain: Describe the capabilities of Microsoft security solutions

Question 23: Protection against malicious email links and attachments

Scenario: Users receive phishing emails that contain malicious links and weaponized attachments. The organization uses Microsoft 365 and wants advanced protection for Exchange Online, SharePoint, OneDrive, and Teams collaboration content.

Choose one answer.

  1. Microsoft Defender for Office 365
  2. Microsoft Entra Permissions Management
  3. Microsoft Purview Insider Risk Management
  4. Azure Network Watcher

Correct answer: A — Microsoft Defender for Office 365

Explanation: Microsoft Defender for Office 365 protects Microsoft 365 collaboration workloads from threats such as phishing, malicious links, and malicious attachments. Capabilities include Safe Links, Safe Attachments, anti-phishing policies, investigation, and response features.

Why the other options are wrong

  • B. Entra Permissions Management focuses on cloud infrastructure entitlement management, not email protection.
  • C. Insider Risk Management helps identify risky insider activities; it is not the primary anti-phishing and attachment detonation solution.
  • D. Azure Network Watcher monitors and diagnoses Azure network resources.

Official reference: Microsoft Defender for Office 365 overview

Domain: Describe the capabilities of Microsoft security solutions

Question 24: Cloud workload protection and posture management

Scenario: An organization runs virtual machines, containers, databases, and storage accounts in Azure. Security leaders want recommendations to improve cloud security posture and workload protection capabilities for cloud resources.

Choose one answer.

  1. Microsoft Priva
  2. Microsoft Entra External ID
  3. Microsoft Purview Data Map
  4. Microsoft Defender for Cloud

Correct answer: D — Microsoft Defender for Cloud

Explanation: Microsoft Defender for Cloud provides cloud security posture management and cloud workload protection. It helps assess resource configurations, provides security recommendations, and can enable Defender plans for workloads such as servers, storage, databases, containers, and more.

Why the other options are wrong

  • A. Microsoft Priva focuses on privacy risk management and privacy subject requests.
  • B. Microsoft Entra External ID supports external identity scenarios, not cloud workload protection.
  • C. Microsoft Purview Data Map supports data discovery and governance, not Azure workload threat protection.

Official reference: What is Microsoft Defender for Cloud?

Domain: Describe the capabilities of Microsoft security solutions

Question 25: Cloud-native SIEM and SOAR

Scenario: A security team needs to collect security logs from Microsoft services, Azure resources, and third-party systems. Analysts need analytics rules, hunting queries, workbooks, and automated response playbooks.

Choose one answer.

  1. Microsoft Sentinel
  2. Microsoft Entra Verified ID
  3. Azure Blueprints
  4. Microsoft Purview Records Management

Correct answer: A — Microsoft Sentinel

Explanation: Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution. It can ingest data from many sources, run analytics, support threat hunting, and automate response with playbooks.

Why the other options are wrong

  • B. Microsoft Entra Verified ID supports decentralized identity credentials, not SIEM/SOAR operations.
  • C. Azure Blueprints helped define repeatable Azure environments, but it is not the Sentinel security analytics platform.
  • D. Records Management handles retention and records in Microsoft Purview, not security event correlation and response.

Official reference: What is Microsoft Sentinel?

Domain: Describe the capabilities of Microsoft security solutions

Question 26: Discovering and controlling SaaS app usage

Scenario: The security team suspects that employees are using unsanctioned SaaS applications. They want to discover cloud app usage, assess app risk, apply app governance, and control sessions for selected cloud apps.

Choose one answer.

  1. Microsoft Defender for Identity
  2. Microsoft Defender for Cloud Apps
  3. Azure Firewall
  4. Microsoft Purview Audit

Correct answer: B — Microsoft Defender for Cloud Apps

Explanation: Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) capability. It helps discover shadow IT, assess cloud app risk, apply app governance, and protect cloud app sessions with policy controls.

Why the other options are wrong

  • A. Defender for Identity detects identity-based threats using on-premises Active Directory signals.
  • C. Azure Firewall is a managed network firewall for Azure resources, not a SaaS discovery and CASB platform.
  • D. Microsoft Purview Audit records user and admin activities for investigation and compliance purposes; it does not provide full CASB controls.

Official reference: What is Microsoft Defender for Cloud Apps?

Domain: Describe the capabilities of Microsoft security solutions

Question 27: Measuring security posture improvements

Scenario: A CISO wants a measurable way to review recommended security actions across the Microsoft environment. The team wants a score that improves as recommended actions are completed and helps prioritize security posture work.

Choose one answer.

  1. Compliance Manager improvement score only
  2. Microsoft Secure Score
  3. Azure Cost Management budgets
  4. Microsoft Entra entitlement management catalogs

Correct answer: B — Microsoft Secure Score

Explanation: Microsoft Secure Score provides a measurement of an organization’s security posture and recommends improvement actions. Completing recommended actions can increase the score and help teams prioritize security hardening.

Why the other options are wrong

  • A. Compliance Manager has an improvement score for compliance posture, but the security posture recommendation score in this scenario is Microsoft Secure Score.
  • C. Azure Cost Management budgets track spend, not security posture.
  • D. Entitlement management catalogs organize access packages and governance workflows, not overall security recommendations.

Official reference: Microsoft Secure Score

Domain: Describe the capabilities of Microsoft security solutions

Question 28: Protecting Azure resources from volumetric DDoS attacks

Scenario: A public-facing Azure application must be protected from large-scale network-layer distributed denial-of-service attacks. The company wants an Azure-native service that provides enhanced DDoS mitigation for protected public IP resources.

Choose one answer.

  1. Azure DDoS Protection
  2. Microsoft Defender for Office 365
  3. Microsoft Purview Data Loss Prevention
  4. Microsoft Entra ID Protection

Correct answer: A — Azure DDoS Protection

Explanation: Azure DDoS Protection helps protect Azure resources with public IP addresses from distributed denial-of-service attacks. It provides enhanced mitigation capabilities beyond the platform’s basic infrastructure protection.

Why the other options are wrong

  • B. Defender for Office 365 protects Microsoft 365 collaboration workloads from email and collaboration threats.
  • C. Purview DLP helps prevent sensitive information from being shared inappropriately.
  • D. Entra ID Protection detects identity risks, such as risky users and risky sign-ins.

Official reference: What is Azure DDoS Protection?

Domain: Describe the capabilities of Microsoft security solutions

Question 29: Storing secrets and encryption keys

Scenario: A development team needs a centralized Azure service to store application secrets, certificates, and cryptographic keys. Applications should retrieve secrets securely instead of storing them in source code or configuration files.

Choose one answer.

  1. Azure Key Vault
  2. Azure Monitor Metrics
  3. Microsoft Defender Vulnerability Management
  4. Microsoft Purview Information Protection

Correct answer: A — Azure Key Vault

Explanation: Azure Key Vault is used to safeguard cryptographic keys, secrets, and certificates. It helps centralize secret management and reduces the need to store sensitive values in application code or local configuration.

Why the other options are wrong

  • B. Azure Monitor Metrics collects and analyzes platform and resource metrics; it does not store secrets.
  • C. Defender Vulnerability Management helps discover, assess, and remediate vulnerabilities, not store keys and certificates.
  • D. Purview Information Protection classifies, labels, and protects sensitive information, but it is not a key vault for application secrets.

Official reference: Azure Key Vault overview

Domain: Describe the capabilities of Microsoft security solutions

Question 30: Detecting identity threats in on-premises Active Directory

Scenario: A company still uses on-premises Active Directory Domain Services. The security team wants to detect suspicious activities such as reconnaissance, lateral movement, and compromised identities by analyzing signals from domain controllers.

Choose one answer.

  1. Microsoft Defender for Cloud
  2. Microsoft Defender for Identity
  3. Azure App Configuration
  4. Microsoft Priva Privacy Risk Management

Correct answer: B — Microsoft Defender for Identity

Explanation: Microsoft Defender for Identity monitors signals from on-premises Active Directory to detect identity-based threats, compromised identities, and malicious insider actions. It is especially relevant when scenarios mention domain controllers and AD DS threat detection.

Why the other options are wrong

  • A. Defender for Cloud focuses on cloud security posture management and workload protection.
  • C. Azure App Configuration centrally manages application configuration settings; it is not an identity threat detection product.
  • D. Microsoft Priva helps manage privacy risks and privacy subject requests, not AD DS threat detection.

Official reference: What is Microsoft Defender for Identity?

Answer key: SC-900 Questions 21-30

Question Correct answer Objective cue
21 B — Microsoft Defender XDR Unified incident correlation across Microsoft security workloads
22 C — Microsoft Defender for Endpoint Endpoint detection and response
23 A — Microsoft Defender for Office 365 Phishing, Safe Links, Safe Attachments, Microsoft 365 collaboration protection
24 D — Microsoft Defender for Cloud Cloud security posture management and workload protection
25 A — Microsoft Sentinel Cloud-native SIEM and SOAR
26 B — Microsoft Defender for Cloud Apps CASB, SaaS discovery, app governance, session controls
27 B — Microsoft Secure Score Security posture measurement and improvement actions
28 A — Azure DDoS Protection Network-layer DDoS mitigation for Azure public IP resources
29 A — Azure Key Vault Secrets, certificates, and cryptographic key storage
30 B — Microsoft Defender for Identity On-premises AD DS identity threat detection
Watch out: Microsoft product names sound similar on purpose — or at least it feels that way during exam prep. If the question says SIEM/SOAR, think Sentinel. If it says endpoint EDR, think Defender for Endpoint. If it says cloud workload posture, think Defender for Cloud. Tiny wording, big points.

Sources