MS-900 Describe Microsoft 365 apps and services Practice Question
A user receives a suspicious email with a link. They report it using the built-in Microsoft 365 reporting tool. Which service will analyze the reported message?
⚠ Common exam trap
It's easy for candidates to confuse Microsoft Defender for Office 365 (which handles email-specific threat analysis and user submissions) with Microsoft Defender XDR (which is the broader correlation engine that ingests alerts from Defender for Office 365 and other sources, but does not itself perform the initial analysis of user-reported messages).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Office 365
Microsoft Defender for Office 365 (MDO) includes the built-in reporting tool that allows users to report suspicious emails directly from Outlook. When a user submits a message via this tool, it is automatically routed to the Microsoft 365 Defender portal's Submissions page, where it is analyzed by MDO's threat protection engines, including detonation in the sandbox environment for URLs and attachments. This analysis determines whether the message is malicious, spam, or a false positive, and updates the tenant's filtering policies accordingly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Office 365
Why this is correct
Microsoft Defender for Office 365 is the dedicated email security workload that receives user-reported phishing or malware reports. It uses threat intelligence, URL and attachment detonation, and automated investigation/response to analyze the message and remediate threats. In this scenario, the reported suspicious link is exactly what MDO's Safe Links and anti-phishing policies are built to evaluate.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM and SOAR platform that aggregates logs from sources like Azure, Microsoft 365, and third-party systems to detect and respond to security incidents. Although it can ingest email telemetry and enrich alerts, it does not natively process user-reported phishing emails or detonate suspicious URLs inside the mail flow. Its role is correlation and investigation, not specialized email-content analysis.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview is centered on compliance, data governance, and risk management—covering areas like data lifecycle management, records management, and eDiscovery. While Purview can apply sensitivity labels or audit email-related events, it does not inspect a reported message for phishing or malware characteristics. Its purpose is protecting and regulating data, not stopping email-borne cyberattacks.
- ✗
Microsoft Defender XDR
Why it's wrong here
Microsoft Defender XDR is an integrated security suite that unifies signals from Microsoft Defender for Office 365, Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps. It can present email-related incidents, but it is not the component that actually analyzes a reported suspicious link; that work is performed by the MDO workload. Choosing XDR is less precise because it is the overarching platform, not the service responsible for submitted email inspection.
Go deeper
Related to this question
Learn chapter
Microsoft 365 SLAs and Service Guarantees
Key term
Microsoft Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email and collaboration security service that protects organizations against malicious threats like phishing, malware, and spam in email messages and Office 365 apps.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.