Describe capabilities of Microsoft Sentinel
Objective microsoft.sentinel sits in Describe capabilities of Microsoft security solutions, which carries 38% of the SCI Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
A security analyst opens the Microsoft Defender portal and sees one view combining detections, impacted assets, and automated actions across products. Which Defender XDR capability provides this view?
The concept
Capabilities in a cross-product suite sit at different layers and are easy to conflate. Correlating alerts into one investigable case is a grouping function. Querying raw telemetry is an analysis function. Remediating a host without an operator is a response function. A question that describes what an analyst sees, rather than what the system does to the data, is asking about the presentation layer.
Why this answer
The analyst describes a display, not an action the system took. Detections, impacted assets and automated actions from separate products are being rendered together in one console, which is the consolidated view rather than any single correlation, hunting or remediation feature.
- AThe combined incidents queue groups alerts and assets into incidents for prioritization, but it is a distinct feature from the general unified display view.
- BSelf-healing describes automated remediation of compromised assets, not a display feature for viewing information.
- CCross-product threat hunting refers to querying raw historic signal data, not a consolidated view of alerts and actions.
- Correct: the scenario describes a view, not a function.
- EAutomatic response to threats describes real-time signal sharing between products to stop an attack, not a display view.
Now you: objective microsoft.sentinel questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
Defender for Endpoint detects a malicious file on a device. Defender XDR then instructs Defender for Office 365 to scan and remove the same file from every mailbox in the organization. Which capability is this?
Sample question 2 of 3
A team runs a Defender XDR hunting query for the past 45 days against raw signals from Defender for Cloud, which protects Azure workloads. Which outcome results from this request?
Sample question 3 of 3
A security team wants one central location that shows all Microsoft Defender XDR detections, impacted assets, and automated actions taken across products. Which portal provides this unified view?
Full SCI Fundamentals question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.