sc-900 Practice Question 1799
Exam: sc-900
Domain: Describe the capabilities of Microsoft security solutions
Topic: Describe Microsoft Defender and Sentinel
Difficulty: medium
Contoso Ltd is evaluating the use of Microsoft 365 Defender for their security needs. They want to understand how it differs from traditional SIEM solutions and SOAR platforms. Which of the following statements accurately describes a key difference between Microsoft 365 Defender and traditional SIEM/SOAR solutions? Explain your choice and why the other options are incorrect.
Answer Options
A
Microsoft 365 Defender does not offer advanced analytics capabilities.
B
Microsoft 365 Defender provides integrated security for Microsoft 365 services, while SIEM/SOAR solutions often focus on log correlation and incident response.
C
Microsoft 365 Defender is a standalone product that does not integrate with other Microsoft 365 services.
D
Microsoft 365 Defender cannot perform threat hunting.
Correct Answer
B: Microsoft 365 Defender provides integrated security for Microsoft 365 services, while SIEM/SOAR solutions often focus on log correlation and incident response.
Explanation
The correct answer is B. Microsoft 365 Defender provides integrated security capabilities for Microsoft 365 services, whereas traditional SIEM and SOAR solutions typically focus on log correlation and incident response across various systems. Option A is incorrect because it suggests that Microsoft 365 Defender lacks advanced analytics, which is not true; it offers robust analytics tailored to Microsoft 365 services. Option C is incorrect as it implies that Microsoft 365 Defender is a standalone product, when in fact it integrates with other Microsoft 365 services. Option D is incorrect because it suggests that Microsoft 365 Defender cannot perform threat hunting, which is a core feature of the service.