MS-900 Describe Microsoft 365 apps and services Practice Question
A company uses Microsoft 365 E5 licenses. The security team wants to automatically remediate advanced threats detected on endpoints without manual intervention. Which Microsoft 365 service should they use?
⚠ Common exam trap
Many exam-takers confuse Microsoft Sentinel's SIEM/SOAR capabilities with automated endpoint remediation, but Sentinel requires integration with Defender XDR to execute such actions, whereas Defender XDR provides native automated remediation directly on endpoints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR
Microsoft Defender XDR (Extended Detection and Response) is the correct service because it provides automated investigation and remediation capabilities for advanced threats detected on endpoints. It uses AI-driven playbooks to automatically contain or remove threats without manual intervention, which aligns directly with the security team's requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Intune
Why it's wrong here
Microsoft Intune is a cloud-based enterprise mobility management (EMM) service that handles mobile device management (MDM) and mobile application management (MAM). It is used to enforce configuration policies, deploy apps, and ensure device compliance, but it does not perform automated investigation or remediation of cyber threats. While Intune can be used to remotely wipe or retire a device after a compromise, it lacks the built-in detection engines and automatic response capabilities that define an endpoint detection and response (EDR) tool.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview is a comprehensive set of solutions for data governance, compliance, and risk management, including data classification, data loss prevention (DLP), eDiscovery, and insider risk management. It is designed to help organizations meet regulatory requirements, protect sensitive information, and manage legal discovery, not to identify or automatically remediate active security threats. Purview's primary focus is on data that is at rest or in use, whereas automated threat remediation requires real-time telemetry and response actions on live endpoints, which is not its purpose.
- ✓
Microsoft Defender XDR
Why this is correct
Microsoft Defender XDR (formerly Microsoft 365 Defender) is the correct answer because it is a unified security platform that provides automated investigation and remediation across endpoints, email, identities, and cloud apps. It uses the Microsoft Defender for Endpoint EDR engine, which continuously monitors endpoint behaviors, detects advanced threats using AI and machine learning, and automatically executes response actions such as quarantining malicious files, isolating compromised devices, blocking indicators, and rolling back registry changes. These automated response playbooks reduce the time to respond and are precisely what the security team needs for proactive threat remediation.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native security information and event management (SIEM) plus security orchestration, automation, and response (SOAR) solution. While Sentinel can collect security telemetry from various sources and run automated playbooks to respond to incidents, it is fundamentally a log analytics and alert correlation platform, not an endpoint remediation engine. Its automation is driven by custom analytics rules and workflows that require configuration, whereas the automatic endpoint remediation described in the scenario is a built-in feature of Microsoft Defender XDR. Sentinel typically complements Defender XDR by providing broader visibility across the enterprise, but it does not inherently remediate endpoints on its own.
Go deeper
Related to this question
Learn chapter
Microsoft 365 SLAs and Service Guarantees
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.