MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A user reports receiving a phishing email that bypassed Exchange Online Protection (EOP). You need to investigate the threat and automate a response across email, endpoints, and identities. Which Microsoft 365 security solution should you use?
⚠ Common exam trap
The trap here is that candidates often pick Microsoft Defender for Office 365 (Option B) because the question mentions a phishing email, but they overlook the requirement to automate a response across email, endpoints, and identities, which only a cross-domain solution like Defender XDR can fulfill.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR
Microsoft Defender XDR (Extended Detection and Response) is the correct choice because it provides a unified, cross-domain security solution that correlates signals across email, endpoints, and identities. When a phishing email bypasses Exchange Online Protection (EOP), Defender XDR can automatically trigger an investigation and response (e.g., remediating the email, isolating the affected endpoint, and resetting the compromised user's credentials) through its automated incident response and playbooks, leveraging data from Defender for Office 365, Defender for Endpoint, and Microsoft Entra ID Protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM/SOAR that aggregates security data from many sources and can trigger automated playbooks, but it does not natively correlate and remediate threats across email, endpoints, and identities in a single integrated response loop. In this scenario, where a phishing email has bypassed email protection, Sentinel would require custom analytics rules and connector configurations to piece together the attack chain, whereas Microsoft Defender XDR provides out-of-the-box cross-domain correlation and automated containment. Thus, Sentinel is not the correct primary solution for automated cross-domain response.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 secures Exchange Online and SharePoint/OneDrive by filtering malicious email and links, but it is scoped to email and collaboration workloads only. It cannot directly investigate or contain an endpoint that may have been compromised after a user clicked a phishing link, nor does it natively extend to identity-based alerts. For a phishing email that bypassed email protection, Defender for Office 365 alone lacks the broader telemetry and automatic response needed across endpoints and identities, so it does not satisfy the cross-domain requirement.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Microsoft Defender for Endpoint focuses on protecting Windows/macOS/Linux endpoints with vulnerability management, endpoint detection, and response, but it does not analyze email headers, message payloads, or mailbox threat data. Even if a user clicked a phishing link, Defender for Endpoint would see only the endpoint-side artifacts and would not automatically correlate that activity with the original email or the user's identity signals. Additionally, it lacks native identity-based remediation, so it cannot provide the unified cross-domain automated response described in the scenario.
- ✓
Microsoft Defender XDR
Why this is correct
Microsoft Defender XDR (formerly Microsoft 365 Defender) unifies signals from Defender for Office 365, Defender for Endpoint, Defender for Identity, and Microsoft Purview into a single incident model. It automatically correlates a phishing email with subsequent endpoint compromises and identity anomalies, then executes built-in automated response actions such as quarantining email, isolating devices, or disabling accounts. This native cross-domain correlation and automated remediation make it the correct primary solution for a phishing email that bypassed email protection and may have impacted multiple domains.
Go deeper
Related to this question
Learn chapter
Microsoft 365 vs Office 365: What Changed
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.