MS-900 Describe Microsoft 365 apps and services Practice Question
An organization uses Microsoft 365 E5 and wants to implement a solution that automatically detects and remediates security incidents across identities, endpoints, and email. Which Microsoft 365 service should they use?
⚠ Common exam trap
Test-takers frequently confuse Microsoft Defender XDR with its individual component products (like Defender for Endpoint or Defender for Office 365), mistakenly assuming that a single-domain solution can meet a cross-domain requirement, or they overestimate Microsoft Sentinel's out-of-the-box automation capabilities versus its actual SIEM-centric, custom-playbook nature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR
Microsoft Defender XDR (Extended Detection and Response) is the correct choice because it provides a unified, cross-domain security solution that automatically correlates alerts and orchestrates remediation across identities, endpoints, email, and cloud apps. This aligns directly with the requirement to detect and remediate security incidents across identities, endpoints, and email, leveraging the Microsoft 365 Defender portal to break down silos between individual security products.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender XDR
Why this is correct
Microsoft Defender XDR is the correct choice because it natively unifies telemetry from Microsoft 365 E5 across endpoints, email, identities, cloud apps, and data into a single incident queue. Its AI-driven correlation and automated response capabilities allow security teams to detect and remediate multi-stage attacks that span these domains, which is the very definition of extended detection and response (XDR).
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Microsoft Defender for Endpoint is a dedicated endpoint detection and response (EDR) solution that provides deep visibility and protection for devices, including endpoint vulnerability management and automated investigation. However, it operates only on the device plane and does not ingest or correlate signals from email, identities, or cloud apps, so it cannot fulfill the organization's need for a cross-domain XDR capability.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) platform that aggregates logs from a wide range of sources for custom analytics and incident response. While it can consume Microsoft 365 signals, it is not a built-in XDR solution; it requires configuration of data connectors, analytics rules, and playbooks, and it does not provide the native, automated cross-domain correlation that Defender XDR delivers out of the box.
- ✗
Microsoft Entra ID Protection
Why it's wrong here
Microsoft Entra ID Protection focuses exclusively on the identity plane, assessing sign-in and user risks, and can trigger conditional access policies or require MFA when anomalies are detected. It does not analyze endpoint telemetry, email content, or cloud app behavior, so it cannot correlate incidents across multiple domains and is not a substitute for an XDR solution.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Global Service Architecture
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.