Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

A user receives a suspicious email with a link. They report it using the built-in Microsoft 365 reporting tool. Which service will analyze the reported message?

⚠ Common exam trap

It's easy for candidates to confuse Microsoft Defender for Office 365 (which handles email-specific threat analysis and user submissions) with Microsoft Defender XDR (which is the broader correlation engine that ingests alerts from Defender for Office 365 and other sources, but does not itself perform the initial analysis of user-reported messages).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Office 365

Microsoft Defender for Office 365 (MDO) includes the built-in reporting tool that allows users to report suspicious emails directly from Outlook. When a user submits a message via this tool, it is automatically routed to the Microsoft 365 Defender portal's Submissions page, where it is analyzed by MDO's threat protection engines, including detonation in the sandbox environment for URLs and attachments. This analysis determines whether the message is malicious, spam, or a false positive, and updates the tenant's filtering policies accordingly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Defender for Office 365

    Why this is correct

    Microsoft Defender for Office 365 is the dedicated email security workload that receives user-reported phishing or malware reports. It uses threat intelligence, URL and attachment detonation, and automated investigation/response to analyze the message and remediate threats. In this scenario, the reported suspicious link is exactly what MDO's Safe Links and anti-phishing policies are built to evaluate.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM and SOAR platform that aggregates logs from sources like Azure, Microsoft 365, and third-party systems to detect and respond to security incidents. Although it can ingest email telemetry and enrich alerts, it does not natively process user-reported phishing emails or detonate suspicious URLs inside the mail flow. Its role is correlation and investigation, not specialized email-content analysis.

  • ✗

    Microsoft Purview

    Why it's wrong here

    Microsoft Purview is centered on compliance, data governance, and risk management—covering areas like data lifecycle management, records management, and eDiscovery. While Purview can apply sensitivity labels or audit email-related events, it does not inspect a reported message for phishing or malware characteristics. Its purpose is protecting and regulating data, not stopping email-borne cyberattacks.

  • ✗

    Microsoft Defender XDR

    Why it's wrong here

    Microsoft Defender XDR is an integrated security suite that unifies signals from Microsoft Defender for Office 365, Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps. It can present email-related incidents, but it is not the component that actually analyzes a reported suspicious link; that work is performed by the MDO workload. Choosing XDR is less precise because it is the overarching platform, not the service responsible for submitted email inspection.

Go deeper

Related to this question

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.