Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

An organization wants to monitor and respond to security incidents across their Microsoft 365 environment, including email, endpoints, and cloud apps. Which solution should they deploy?

⚠ Common exam trap

MS-900 often tests the difference between XDR (Defender XDR) and SIEM (Sentinel) — candidates may choose Sentinel thinking it covers all Microsoft 365 workloads, but the question specifically asks for integrated monitoring and response across email, endpoints, and cloud apps, which is Defender XDR's role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender XDR

Microsoft Defender XDR (formerly Microsoft 365 Defender) is a unified extended detection and response solution that correlates signals across email (Defender for Office 365), endpoints (Defender for Endpoint), identities (Defender for Identity), and cloud apps (Defender for Cloud Apps). It provides a single portal for monitoring and responding to security incidents across the Microsoft 365 environment, making it the correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is a cloud-based endpoint management service that provides mobile device management (MDM) and mobile application management (MAM), such as enforcing compliance policies, deploying software, and remote wiping devices. While it improves the security posture of endpoints, it does not ingest signals across email, identities, and cloud apps, nor does it provide alert correlation and automated incident response. Therefore, Intune fails the scenario because it is an administrative tool for managing devices, not a security solution that monitors and responds to cross-domain threats.

  • ✓

    Microsoft Defender XDR

    Why this is correct

    Microsoft Defender XDR (formerly Microsoft 365 Defender) is an integrated XDR service that natively aggregates signals from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps. It uses AI and automated response actions to investigate and remediate incidents in a single console, covering email, endpoints, identities, and applications. This exactly matches the requirement to monitor and respond to security incidents across the full Microsoft 365 environment, making it the correct choice.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM and SOAR platform that collects telemetry from diverse sources like Azure, Microsoft 365, and third-party tools, then applies analytics rules to detect and respond to threats. Although it can ingest Microsoft 365 data and orchestrate response playbooks, it is an Azure service requiring custom configuration rather than a built-in Microsoft 365 security solution. The question specifically asks for a solution within Microsoft 365, so Sentinel’s broader, less integrated nature makes it incorrect for this scenario.

  • ✗

    Microsoft Defender for Office 365

    Why it's wrong here

    Microsoft Defender for Office 365 provides advanced threat protection specifically for email, SharePoint, OneDrive, and Teams. It fails this scenario because it lacks the capability to monitor and respond to security incidents on *endpoints* and across the *full range of cloud apps* beyond the core Office 365 suite, which the question explicitly requires. This option is tempting as it addresses a significant portion of the Microsoft 365 environment and would be correct if the scope were limited to advanced protection against threats within those specific Office 365 services.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.