Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A security analyst is reviewing logs to detect unusual login patterns, such as multiple failed login attempts from different geographic locations within a short period. The goal is to identify potential unauthorized access or brute-force attacks. Which security concept is the analyst applying?

  1. AData Governance
  2. BSecurity Information and Event Management (SIEM)
  3. CThreat Protection
  4. DVulnerability Management
Show answer & explanation

Correct answer: C. Threat Protection

Threat Protection encompasses measures to prevent, detect, and respond to cyber threats. Analyzing login patterns to detect unauthorized access or attacks falls under the detection and response aspects of threat protection.

Why the other options are wrong

  • A. Data Governance deals with managing data assets, not security incidents or active threats.
  • B. SIEM is a tool/system used for threat protection, but Threat Protection is the broader concept of what the analyst is doing.
  • D. Vulnerability Management focuses on identifying and remediating weaknesses, not detecting active attacks.

Threat Protection

A comprehensive security approach that involves identifying, preventing, detecting, and responding to cyber threats and malicious activities.

  • Includes antivirus, anti-malware, firewall, intrusion detection.
  • Aims to safeguard systems and data from various cyberattacks.
  • Often involves continuous monitoring and analysis of security data.

Memory trick: Threat Protection: The watchful guard against bad guys.

More Describe the concepts of security, compliance, and identity questions