Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

An organization uses Microsoft 365 E5 and wants to implement a solution that automatically detects and remediates security incidents across identities, endpoints, and email. Which Microsoft 365 service should they use?

⚠ Common exam trap

Test-takers frequently confuse Microsoft Defender XDR with its individual component products (like Defender for Endpoint or Defender for Office 365), mistakenly assuming that a single-domain solution can meet a cross-domain requirement, or they overestimate Microsoft Sentinel's out-of-the-box automation capabilities versus its actual SIEM-centric, custom-playbook nature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender XDR

Microsoft Defender XDR (Extended Detection and Response) is the correct choice because it provides a unified, cross-domain security solution that automatically correlates alerts and orchestrates remediation across identities, endpoints, email, and cloud apps. This aligns directly with the requirement to detect and remediate security incidents across identities, endpoints, and email, leveraging the Microsoft 365 Defender portal to break down silos between individual security products.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Defender XDR

    Why this is correct

    Microsoft Defender XDR is the correct choice because it natively unifies telemetry from Microsoft 365 E5 across endpoints, email, identities, cloud apps, and data into a single incident queue. Its AI-driven correlation and automated response capabilities allow security teams to detect and remediate multi-stage attacks that span these domains, which is the very definition of extended detection and response (XDR).

  • ✗

    Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint is a dedicated endpoint detection and response (EDR) solution that provides deep visibility and protection for devices, including endpoint vulnerability management and automated investigation. However, it operates only on the device plane and does not ingest or correlate signals from email, identities, or cloud apps, so it cannot fulfill the organization's need for a cross-domain XDR capability.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) platform that aggregates logs from a wide range of sources for custom analytics and incident response. While it can consume Microsoft 365 signals, it is not a built-in XDR solution; it requires configuration of data connectors, analytics rules, and playbooks, and it does not provide the native, automated cross-domain correlation that Defender XDR delivers out of the box.

  • ✗

    Microsoft Entra ID Protection

    Why it's wrong here

    Microsoft Entra ID Protection focuses exclusively on the identity plane, assessing sign-in and user risks, and can trigger conditional access policies or require MFA when anomalies are detected. It does not analyze endpoint telemetry, email content, or cloud app behavior, so it cannot correlate incidents across multiple domains and is not a substitute for an XDR solution.

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.