MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A company is adopting Microsoft 365 and wants to ensure they can investigate security incidents across email, endpoints, and identities in a unified console. Which Microsoft 365 workload should they use?
⚠ Common exam trap
Candidates often confuse Microsoft Sentinel (a SIEM) with Microsoft Defender XDR (an XDR), but Sentinel is for ingesting logs from any source and requires manual correlation, while Defender XDR provides native, automated cross-domain incident correlation specifically for Microsoft 365 workloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR
Microsoft Defender XDR (Extended Detection and Response) is the correct choice because it provides a unified console for investigating security incidents across email, endpoints, and identities. It correlates alerts from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps into a single incident queue, enabling cross-domain threat hunting and automated response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Intune
Why it's wrong here
Microsoft Intune is a cloud-based endpoint management service (MDM/MAM) that enforces device compliance, deploys applications, and configures device settings. While it can integrate with Defender for Endpoint for device reporting, it does not aggregate security alerts or provide an incident investigation experience. Intune is a policy and management plane, not a security operations console that unifies alerts across email, identities, and endpoints.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution that ingests telemetry from across the enterprise into a Log Analytics workspace. Although it can consume Microsoft 365 Defender's signals, it is a separate Azure service requiring significant setup for analytics rules and connectors. For an organization adopting Microsoft 365, the native unified security console is Defender XDR; Sentinel is typically used for cross-cloud and third-party data correlation, not as the built-in incident investigation experience.
- ✗
Microsoft Purview Compliance Portal
Why it's wrong here
Microsoft Purview Compliance Portal is designed for data governance, information protection, eDiscovery, and compliance management, including Data Loss Prevention (DLP) policies and retention labels. It assists with audits and legal holds but does not provide real-time security incident investigation, threat hunting, or coordinated response actions. In an active attack, security teams would not use Purview to triage incidents; it is a compliance and risk tool that supports regulatory obligations rather than the unified SecOps console.
- ✓
Microsoft Defender XDR
Why this is correct
Microsoft Defender XDR is the unified security operations platform native to Microsoft 365, correlating signals from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps into a single incident queue. It provides automated investigation and response, an attack story, and threat analytics, enabling security teams to investigate and remediate across email, endpoints, identities, and cloud apps from one console. This directly meets the requirement for Microsoft 365 security incident investigation, making it the correct answer.
Go deeper
Related to this question
Learn chapter
Zero Trust Security Principles in Microsoft 365
Key term
Defender for Identity
Defender for Identity is a cloud-based security solution that detects, investigates, and responds to advanced identity threats targeting on-premises Active Directory and cloud identities.
Key term
Defender for Cloud
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides unified security management and threat protection across hybrid and multi-cloud environments.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.