Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A company is adopting Microsoft 365 and wants to ensure they can investigate security incidents across email, endpoints, and identities in a unified console. Which Microsoft 365 workload should they use?

⚠ Common exam trap

Candidates often confuse Microsoft Sentinel (a SIEM) with Microsoft Defender XDR (an XDR), but Sentinel is for ingesting logs from any source and requires manual correlation, while Defender XDR provides native, automated cross-domain incident correlation specifically for Microsoft 365 workloads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender XDR

Microsoft Defender XDR (Extended Detection and Response) is the correct choice because it provides a unified console for investigating security incidents across email, endpoints, and identities. It correlates alerts from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps into a single incident queue, enabling cross-domain threat hunting and automated response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is a cloud-based endpoint management service (MDM/MAM) that enforces device compliance, deploys applications, and configures device settings. While it can integrate with Defender for Endpoint for device reporting, it does not aggregate security alerts or provide an incident investigation experience. Intune is a policy and management plane, not a security operations console that unifies alerts across email, identities, and endpoints.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution that ingests telemetry from across the enterprise into a Log Analytics workspace. Although it can consume Microsoft 365 Defender's signals, it is a separate Azure service requiring significant setup for analytics rules and connectors. For an organization adopting Microsoft 365, the native unified security console is Defender XDR; Sentinel is typically used for cross-cloud and third-party data correlation, not as the built-in incident investigation experience.

  • ✗

    Microsoft Purview Compliance Portal

    Why it's wrong here

    Microsoft Purview Compliance Portal is designed for data governance, information protection, eDiscovery, and compliance management, including Data Loss Prevention (DLP) policies and retention labels. It assists with audits and legal holds but does not provide real-time security incident investigation, threat hunting, or coordinated response actions. In an active attack, security teams would not use Purview to triage incidents; it is a compliance and risk tool that supports regulatory obligations rather than the unified SecOps console.

  • ✓

    Microsoft Defender XDR

    Why this is correct

    Microsoft Defender XDR is the unified security operations platform native to Microsoft 365, correlating signals from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps into a single incident queue. It provides automated investigation and response, an attack story, and threat analytics, enabling security teams to investigate and remediate across email, endpoints, identities, and cloud apps from one console. This directly meets the requirement for Microsoft 365 security incident investigation, making it the correct answer.

Go deeper

Related to this question

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.