Describe the capabilities of Microsoft security solutions
Microsoft Sentinel: SIEM and SOAR
CoreSeparate security analytics from orchestration and recognize Sentinel detection and response capabilities.
Aligned to the SC-900 skills measured as of July 28, 2026; product behavior verified September 10, 2026.
Why this matters
Security teams need a broad view of signals and repeatable ways to investigate and respond. Microsoft Sentinel provides cloud-native security analytics and automation.
Must Know
- A SIEM collects and correlates security data to support visibility, analytics, alerting, investigation, and threat hunting.
- SOAR orchestrates security processes and automates response actions through workflows.
- Microsoft Sentinel is Microsoft's cloud-native SIEM and security solution with SOAR capabilities.
- Data connectors bring supported data into Sentinel; analytics can produce alerts and incidents from suspicious patterns.
- Threat intelligence, UEBA, hunting, workbooks, incidents, automation rules, and playbooks support detection, investigation, visualization, and response.
Compare and Distinguish
- SIEM vs SOAR: analyze and correlate security data versus orchestrate and automate response.
- Analytics rule vs playbook: detect suspicious activity versus run an automated response workflow.
- Threat hunting vs incident response: proactively search for threats versus investigate and contain a surfaced incident.
- Sentinel vs Defender XDR: broad SIEM/SOAR data and operations versus XDR correlation across Microsoft Defender protection domains.
Scenario examples
- Sentinel correlates alerts from several data sources into an incident for investigation.
- An automation rule triggers a playbook to perform a repeatable response step.
- An analyst uses hunting queries and threat intelligence to search for activity not yet represented by a known incident.
Exam traps
- SOAR is not another name for log collection.
- A playbook is not the detection rule that originally recognizes suspicious activity.
- Sentinel is not limited to one endpoint product or only Microsoft data sources.
- Automation supports analysts; it does not make every incident safe to close without investigation.
Key takeaways
- SIEM turns security data into visibility and detections.
- SOAR coordinates and automates response.
- Sentinel supports collection, detection, investigation, hunting, visualization, and response.
- Keep analytics and automation roles distinct.
Ready for the quiz?
- Which concept correlates security events?
- Which Sentinel capability runs response workflows?
- How does hunting differ from incident handling?
Related objectives
- D3.3.S1 — Define the concepts of security information and event management (SIEM) and security orchestration automated response (SOAR)
- D3.3.S2 — Describe threat detection and mitigation capabilities in Microsoft Sentinel