Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

An organization uses Microsoft 365 and wants to automatically detect and remediate security incidents across identities, endpoints, and cloud apps. Which Microsoft 365 service should they deploy?

⚠ Common exam trap

Test-takers frequently confuse Microsoft Sentinel (a SIEM) with Microsoft Defender XDR (an XDR), but Sentinel requires manual configuration for automated remediation across domains, whereas Defender XDR provides built-in, cross-domain automated response out of the box.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender XDR

Microsoft Defender XDR (Extended Detection and Response) is the correct choice because it provides a unified, cross-domain security solution that automatically detects and remediates security incidents across identities, endpoints, and cloud apps. It correlates signals from Microsoft Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps to deliver automated investigation and response, aligning directly with the scenario's requirement for holistic incident management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM/SOAR that aggregates logs from Microsoft 365 and external sources, using KQL queries and automation rules to build custom detections and response playbooks. However, it is an Azure service that requires separate data connectors and log ingestion, and it does not provide the native, built-in cross-domain correlation and automated remediation that an XDR delivers for the Microsoft 365 ecosystem. Its automation depends on user-built playbooks rather than the out-of-the-box integrated threat response from Defender XDR.

  • ✗

    Microsoft Purview

    Why it's wrong here

    Microsoft Purview is a suite of data security, governance, and compliance products, covering sensitive data classification, data loss prevention, eDiscovery, and insider risk management. It is designed to identify and protect where data resides, not to detect active cyberattacks or orchestrate automated remediation across endpoints, identities, or cloud apps. While Purview can use policies to enforce compliance controls, its alerts are not the integrated threat detection and response signals that Defender XDR correlates.

  • ✗

    Microsoft Defender for Office 365

    Why it's wrong here

    Microsoft Defender for Office 365 is a purpose-built email security gateway that filters phishing, malware, and unsafe attachments, and it provides threat investigation and automated remediation within Exchange Online, SharePoint Online, Teams, and OneDrive. Its scope is limited to M365 collaboration workloads and does not monitor Windows endpoints, Microsoft Entra ID identities, or non-Microsoft SaaS apps, so it is only a component rather than the full XDR platform. Organizations needing a unified incident lifecycle across the entire environment require Defender XDR.

  • ✓

    Microsoft Defender XDR

    Why this is correct

    Microsoft Defender XDR (formerly Microsoft 365 Defender) unifies telemetry from Defender for Identity, Defender for Endpoint, Defender for Office 365, and Defender for Cloud Apps into a single incident queue, automatically correlating suspicious activities across identities, endpoints, email, and cloud applications. It leverages built-in hunting and automated response playbooks to remediate threats with actions like isolating endpoints, pausing user accounts, or rolling back email messages. This integrated, portfolio-wide automation is exactly the native XDR capability that the organization needs.

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.