Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

A company uses Microsoft 365 E5 licenses. The security team wants to automatically remediate advanced threats detected on endpoints without manual intervention. Which Microsoft 365 service should they use?

⚠ Common exam trap

Many exam-takers confuse Microsoft Sentinel's SIEM/SOAR capabilities with automated endpoint remediation, but Sentinel requires integration with Defender XDR to execute such actions, whereas Defender XDR provides native automated remediation directly on endpoints.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender XDR

Microsoft Defender XDR (Extended Detection and Response) is the correct service because it provides automated investigation and remediation capabilities for advanced threats detected on endpoints. It uses AI-driven playbooks to automatically contain or remove threats without manual intervention, which aligns directly with the security team's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is a cloud-based enterprise mobility management (EMM) service that handles mobile device management (MDM) and mobile application management (MAM). It is used to enforce configuration policies, deploy apps, and ensure device compliance, but it does not perform automated investigation or remediation of cyber threats. While Intune can be used to remotely wipe or retire a device after a compromise, it lacks the built-in detection engines and automatic response capabilities that define an endpoint detection and response (EDR) tool.

  • ✗

    Microsoft Purview

    Why it's wrong here

    Microsoft Purview is a comprehensive set of solutions for data governance, compliance, and risk management, including data classification, data loss prevention (DLP), eDiscovery, and insider risk management. It is designed to help organizations meet regulatory requirements, protect sensitive information, and manage legal discovery, not to identify or automatically remediate active security threats. Purview's primary focus is on data that is at rest or in use, whereas automated threat remediation requires real-time telemetry and response actions on live endpoints, which is not its purpose.

  • ✓

    Microsoft Defender XDR

    Why this is correct

    Microsoft Defender XDR (formerly Microsoft 365 Defender) is the correct answer because it is a unified security platform that provides automated investigation and remediation across endpoints, email, identities, and cloud apps. It uses the Microsoft Defender for Endpoint EDR engine, which continuously monitors endpoint behaviors, detects advanced threats using AI and machine learning, and automatically executes response actions such as quarantining malicious files, isolating compromised devices, blocking indicators, and rolling back registry changes. These automated response playbooks reduce the time to respond and are precisely what the security team needs for proactive threat remediation.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native security information and event management (SIEM) plus security orchestration, automation, and response (SOAR) solution. While Sentinel can collect security telemetry from various sources and run automated playbooks to respond to incidents, it is fundamentally a log analytics and alert correlation platform, not an endpoint remediation engine. Its automation is driven by custom analytics rules and workflows that require configuration, whereas the automatic endpoint remediation described in the scenario is a built-in feature of Microsoft Defender XDR. Sentinel typically complements Defender XDR by providing broader visibility across the enterprise, but it does not inherently remediate endpoints on its own.

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.