SC-900 Security Operations & Threat Protection 3 — Questions and Answers
Question 1: What type of signal does Microsoft Defender for Identity primarily analyze to detect suspicious activity?
- Network packet captures
- Active Directory Domain Services logs and traffic (Correct answer)
- Cloud app access logs
- Endpoint process trees
Correct answer: Active Directory Domain Services logs and traffic
Microsoft Defender for Identity monitors Active Directory Domain Services traffic and logs to detect identity-based attacks such as pass-the-hash and lateral movement.
Question 2: Which Microsoft 365 Defender portal feature provides a unified view of incidents across endpoints, email, identities, and apps?
- Secure Score
- Incidents queue (Correct answer)
- Threat analytics
- Device inventory
Correct answer: Incidents queue
The Incidents queue in the Microsoft 365 Defender portal aggregates correlated alerts from across all Microsoft 365 Defender products into unified incidents.
Question 3: What does the 'Kill Chain' framework help security analysts understand?
- How to configure firewall rules
- The stages an attacker follows from initial access to achieving their goal (Correct answer)
- How to assign role-based access control
- The order in which patches should be applied
Correct answer: The stages an attacker follows from initial access to achieving their goal
The Cyber Kill Chain describes the sequential stages of a cyberattack, helping analysts understand attacker progression and identify where to intervene.
Question 4: A security analyst notices an alert that a user's credentials were used to sign in from two countries within 30 minutes. Which Microsoft service most likely generated this alert?
- Microsoft Defender for Endpoint
- Microsoft Entra ID Protection (Correct answer)
- Microsoft Defender for Cloud
- Microsoft Purview
Correct answer: Microsoft Entra ID Protection
Microsoft Entra ID Protection (formerly Azure AD Identity Protection) detects risky sign-ins such as impossible travel and generates risk alerts.
Question 5: Which SIEM capability allows Microsoft Sentinel to ingest logs from non-Microsoft sources such as firewalls and Linux servers?
- Playbooks
- Workbooks
- Data connectors (Correct answer)
- Hunting queries
Correct answer: Data connectors
Data connectors in Microsoft Sentinel enable log ingestion from hundreds of sources including non-Microsoft devices, services, and platforms.
Question 6: What is the purpose of Microsoft Defender for Cloud Apps' 'Shadow IT Discovery' feature?
- Blocks all unsanctioned cloud app usage permanently
- Identifies cloud apps being used without IT approval (Correct answer)
- Encrypts data stored in sanctioned cloud apps
- Monitors privileged admin activity in Azure
Correct answer: Identifies cloud apps being used without IT approval
Shadow IT Discovery analyzes network traffic logs to identify cloud applications employees are using without official IT approval or security review.
Question 7: Which Microsoft tool provides Threat Intelligence reports to help analysts understand active threat actors and campaigns targeting their industry?
- Microsoft Purview
- Microsoft Sentinel Threat Intelligence (Correct answer)
- Microsoft Entra Permissions Management
- Microsoft Priva
Correct answer: Microsoft Sentinel Threat Intelligence
Microsoft Sentinel's built-in Threat Intelligence features, including MITRE ATT&CK integration and threat actor reports, help analysts contextualize threats relevant to their environment.
What type of signal does Microsoft Defender for Identity primarily analyze to detect suspicious activity?