SC-900 - Microsoft Security Solutions (38% of the exam) - Section 3.3

Describe the capabilities of Microsoft Sentinel.

Describe Microsoft Sentinel as a cloud-native SIEM and SOAR solution that collects, correlates, and analyses security data at scale across an enterprise. Distinguish its threat detection capabilities, such as analytics rules and threat hunting, from its SOAR automation playbooks used to accelerate incident response and mitigation.

SIEMSOARthreat detection and mitigation

Practice question for this objective

Free sampleMicrosoft Security Solutionsmedium

A security operations centre is evaluating Microsoft Sentinel as a cloud-native SIEM and SOAR platform. Which TWO capabilities does Microsoft Sentinel provide? Select TWO.

  • ACollecting and correlating security data at scale across users, devices, apps, and infrastructure. Correct
  • BStoring application secrets, encryption keys, and certificates with managed access control.
  • CContinuously scoring Azure resource configurations against built-in security standards.
  • DAutomating incident response through playbooks that orchestrate actions across connected systems. Correct
  • EBrokering portal-based RDP and SSH sessions to virtual machines without public IPs.
Microsoft Sentinel is a cloud-native SIEM and SOAR that collects and correlates security data at scale and automates incident response with playbooks. As a SIEM, Sentinel collects and correlates telemetry at scale; as a SOAR, it runs playbooks that automate response. Secret storage, posture scoring, and session brokering are Key Vault, Defender for Cloud and Bastion respectively, none of which are Sentinel.

Why A is correct: Sentinel ingests and correlates data at cloud scale from across the estate, a core SIEM function.

Why B is wrong: Storing secrets, keys and certificates is Azure Key Vault, not a function of the Sentinel SIEM.

Why C is wrong: Configuration scoring against standards is Defender for Cloud CSPM, distinct from Sentinel data correlation.

Why D is correct: Playbook-driven automated response is the SOAR side of Sentinel, orchestrating actions on incidents.

Why E is wrong: Portal-based RDP and SSH brokering is Azure Bastion, unrelated to Sentinel's SIEM and SOAR roles.

See more SC-900 practice questions, answers explained.

Exam traps in Microsoft Security Solutions

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-900 bank for this domain.

  • Microsoft Defender for Cloud, the service that strengthens the security posture of cloud resources.

    Why it is wrong: Defender for Cloud focuses on cloud security posture management and workload protection, not on being the cloud-native SIEM described in the grounding.

  • Scheduled rules, which query raw data at regular intervals and raise their own alerts on a threshold.

    Why it is wrong: Scheduled rules generate alerts from their own queries; they do not create incidents from alerts produced by other Microsoft solutions.

  • Analytics rules build the interactive workbooks that visualise Sentinel data for dashboards and reporting.

    Why it is wrong: Tempting because both are Sentinel features, but visualisation is the job of Sentinel workbooks; analytics rules evaluate queries and raise alerts, they do not build dashboards.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.