GregLab | Exam Prep

Describe the capabilities of Microsoft security solutions

Microsoft Sentinel: SIEM and SOAR

Core

Separate security analytics from orchestration and recognize Sentinel detection and response capabilities.

Aligned to the SC-900 skills measured as of July 28, 2026; product behavior verified September 10, 2026.

Why this matters

Security teams need a broad view of signals and repeatable ways to investigate and respond. Microsoft Sentinel provides cloud-native security analytics and automation.

Must Know

  • A SIEM collects and correlates security data to support visibility, analytics, alerting, investigation, and threat hunting.
  • SOAR orchestrates security processes and automates response actions through workflows.
  • Microsoft Sentinel is Microsoft's cloud-native SIEM and security solution with SOAR capabilities.
  • Data connectors bring supported data into Sentinel; analytics can produce alerts and incidents from suspicious patterns.
  • Threat intelligence, UEBA, hunting, workbooks, incidents, automation rules, and playbooks support detection, investigation, visualization, and response.

Compare and Distinguish

  • SIEM vs SOAR: analyze and correlate security data versus orchestrate and automate response.
  • Analytics rule vs playbook: detect suspicious activity versus run an automated response workflow.
  • Threat hunting vs incident response: proactively search for threats versus investigate and contain a surfaced incident.
  • Sentinel vs Defender XDR: broad SIEM/SOAR data and operations versus XDR correlation across Microsoft Defender protection domains.

Scenario examples

  • Sentinel correlates alerts from several data sources into an incident for investigation.
  • An automation rule triggers a playbook to perform a repeatable response step.
  • An analyst uses hunting queries and threat intelligence to search for activity not yet represented by a known incident.

Exam traps

  • SOAR is not another name for log collection.
  • A playbook is not the detection rule that originally recognizes suspicious activity.
  • Sentinel is not limited to one endpoint product or only Microsoft data sources.
  • Automation supports analysts; it does not make every incident safe to close without investigation.

Key takeaways

  • SIEM turns security data into visibility and detections.
  • SOAR coordinates and automates response.
  • Sentinel supports collection, detection, investigation, hunting, visualization, and response.
  • Keep analytics and automation roles distinct.

Ready for the quiz?

  • Which concept correlates security events?
  • Which Sentinel capability runs response workflows?
  • How does hunting differ from incident handling?

Related objectives

  • D3.3.S1 — Define the concepts of security information and event management (SIEM) and security orchestration automated response (SOAR)
  • D3.3.S2 — Describe threat detection and mitigation capabilities in Microsoft Sentinel

Learn more

Free Microsoft Certified: Security, Compliance, and Identity Fundamentals prep

Build focused SC-900 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

SC-900 at a glance

Level
Beginner / Fundamentals
Duration
45 minutes
Questions
No fixed live question count published
Formats
No guaranteed question-type mix
Scoring
Scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not publish a fixed live question count or guarantee a question-type mix for SC-900. This lane plans only multiple-choice and multiple-response exam-style practice; no supplemental matching, ordering, or case-study exercises are planned. Practice percentages do not reproduce Microsoft's scaled scoring, and difficulty labels describe this site's Fundamentals-level scenario complexity rather than a Microsoft-published question rating.

Reference

SC-900 topics and reference map

Study links

SC-900 resources