SC-900 - Microsoft Security Solutions - Section 3.3

Describe the capabilities of Microsoft Sentinel.

Describe Microsoft Sentinel as a cloud-native SIEM and SOAR solution that collects, correlates, and analyses security data at scale across an enterprise. Distinguish its threat detection capabilities, such as analytics rules and threat hunting, from its SOAR automation playbooks used to accelerate incident response and mitigation.

SIEMSOARthreat detection and mitigation

Practice question for this objective

Free sampleMicrosoft Security Solutionsmedium

A security operations centre is evaluating Microsoft Sentinel as a cloud-native SIEM and SOAR platform. Which TWO capabilities does Microsoft Sentinel provide? Select TWO.

  • ACollecting and correlating security data at scale across users, devices, apps, and infrastructure. Correct
  • BStoring application secrets, encryption keys, and certificates with managed access control.
  • CContinuously scoring Azure resource configurations against built-in security standards.
  • DAutomating incident response through playbooks that orchestrate actions across connected systems. Correct
  • EBrokering portal-based RDP and SSH sessions to virtual machines without public IPs.
Microsoft Sentinel is a cloud-native SIEM and SOAR that collects and correlates security data at scale and automates incident response with playbooks. As a SIEM, Sentinel collects and correlates telemetry at scale; as a SOAR, it runs playbooks that automate response. Secret storage, posture scoring, and session brokering are Key Vault, Defender for Cloud and Bastion respectively, none of which are Sentinel.

Why A is correct: Sentinel ingests and correlates data at cloud scale from across the estate, a core SIEM function.

Why B is wrong: Storing secrets, keys and certificates is Azure Key Vault, not a function of the Sentinel SIEM.

Why C is wrong: Configuration scoring against standards is Defender for Cloud CSPM, distinct from Sentinel data correlation.

Why D is correct: Playbook-driven automated response is the SOAR side of Sentinel, orchestrating actions on incidents.

Why E is wrong: Portal-based RDP and SSH brokering is Azure Bastion, unrelated to Sentinel's SIEM and SOAR roles.

See more SC-900 practice questions, answers explained.

More in this domain

Back to all Microsoft Security Solutions objectives, or the SC-900 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.