nerdexam
Microsoft

MS-900 · Question #432

Hotspot Question A company is evaluating security capabilities of Microsoft Sentinel. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each…

The correct answer is The Microsoft cloud native security information event management (SIEM) system receives alerts from a variety of sources and triggers security task processes in response. = Yes; The Microsoft cloud native security orchestration automated response (SOAR) system collects data from a variety of sources, analyzes the data, and automatically generates alerts in response. = Yes; Microsoft Sentinel playbooks can be used to send Microsoft Teams chat messages. = Yes. Microsoft Sentinel is Microsoft's cloud-native SIEM+SOAR solution. As a SIEM, it collects and analyzes data from multiple sources and generates alerts, while as a SOAR platform, it automates responses to those alerts through playbooks and orchestration workflows. The first…

Submitted by fatima_kr· Mar 5, 2026Describe the capabilities of Microsoft security solutions - specifically Microsoft Sentinel as a cloud-native SIEM and SOAR platform (Microsoft SC-900 / SC-200 domain: Security Operations and Threat Protection)

Question

Hotspot Question A company is evaluating security capabilities of Microsoft Sentinel. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibit

MS-900 question #432 exhibit

Answer Area

  • The Microsoft cloud native security information event management (SIEM) system receives alerts from a variety of sources and triggers security task processes in response.Yes
  • The Microsoft cloud native security orchestration automated response (SOAR) system collects data from a variety of sources, analyzes the data, and automatically generates alerts in response.Yes
  • Microsoft Sentinel playbooks can be used to send Microsoft Teams chat messages.Yes

Explanation

Microsoft Sentinel is Microsoft's cloud-native SIEM+SOAR solution. As a SIEM, it collects and analyzes data from multiple sources and generates alerts, while as a SOAR platform, it automates responses to those alerts through playbooks and orchestration workflows. The first statement is correct because Sentinel (as a SOAR) does trigger automated security response tasks (playbooks via Logic Apps) in response to alerts from various sources. The second statement is also marked Yes, though it slightly blurs the lines - in the context of this question, Sentinel's SOAR capability works in conjunction with its SIEM capability to collect, analyze, and respond, making the combined description acceptable. The third statement appears truncated but is also marked Yes, likely referring to Sentinel providing built-in threat intelligence, AI-driven analytics, or incident management capabilities that distinguish it as a unified security operations platform.

Topics

#Microsoft Sentinel#SIEM#SOAR#Security Operations

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice