MS-900 Describe Microsoft 365 apps and services Practice Question
A company uses Microsoft 365 E5 and wants to implement a solution that automatically detects and remediates security incidents across endpoints, email, and identities. Which service should they use?
⚠ Common exam trap
Watch out — candidates often confuse Microsoft Defender for Cloud (a cloud workload protection tool) with Microsoft Defender XDR, or mistakenly think Microsoft Sentinel (a SIEM) is the primary automated remediation tool, when in fact Sentinel requires custom playbooks and is not designed for cross-domain automated remediation out of the box.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR
Microsoft Defender XDR (Extended Detection and Response) is the correct choice because it provides a unified, cross-domain security solution that automatically detects, investigates, and remediates threats across endpoints, email, and identities. It leverages AI and automation to correlate signals from Microsoft Defender for Endpoint, Defender for Office 365, and Defender for Identity, enabling coordinated incident response without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender XDR
Why this is correct
Microsoft Defender XDR is the correct choice because it is a unified extended detection and response (XDR) solution that automatically correlates alerts and signals across endpoints, email, identities, and cloud apps. It provides built-in, out-of-the-box automated response actions such as isolating devices, quarantining files, and blocking accounts, enabling rapid mitigation across the full attack surface. This cross-domain automation makes it an ideal single solution for implementing security incident response in a Microsoft 365 E5 environment.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview is incorrect because it is a data governance, risk, and compliance platform, not a security incident response solution. It handles data classification, retention policies, eDiscovery, and audit logging, but it does not detect threats, correlate security signals, or execute automated remediation. While Purview is valuable for regulatory compliance and data protection, it lacks the detection and response capabilities needed to address active security incidents.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is incorrect because it focuses on cloud security posture management (CSPM) and workload protection for infrastructure such as VMs, containers, and databases across Azure, on-premises, and other clouds. It provides security recommendations and identifies misconfigurations, but it does not provide unified cross-domain incident response across the Microsoft 365 ecosystem. Its scope is limited to the cloud infrastructure layer, not the identity, email, and endpoint coverage that Defender XDR offers.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is incorrect because it is a cloud-native SIEM (Security Information and Event Management) and SOAR platform that aggregates logs from many sources and requires custom analytics rules to detect threats. While it can orchestrate response through playbooks, those playbooks are typically built with Azure Logic Apps and require manual creation and tuning. Unlike Defender XDR, Sentinel does not offer out-of-the-box, automated, cross-domain response that is ready to use immediately, making it less suitable for a straightforward security solution implementation.
Go deeper
Related to this question
Learn chapter
Privileged Identity Management (PIM) in M365
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.