MS-900 Describe Microsoft 365 apps and services Practice Question
An organization wants to monitor and respond to security incidents across their Microsoft 365 environment, including email, endpoints, and cloud apps. Which solution should they deploy?
⚠ Common exam trap
MS-900 often tests the difference between XDR (Defender XDR) and SIEM (Sentinel) — candidates may choose Sentinel thinking it covers all Microsoft 365 workloads, but the question specifically asks for integrated monitoring and response across email, endpoints, and cloud apps, which is Defender XDR's role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR
Microsoft Defender XDR (formerly Microsoft 365 Defender) is a unified extended detection and response solution that correlates signals across email (Defender for Office 365), endpoints (Defender for Endpoint), identities (Defender for Identity), and cloud apps (Defender for Cloud Apps). It provides a single portal for monitoring and responding to security incidents across the Microsoft 365 environment, making it the correct choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Intune
Why it's wrong here
Microsoft Intune is a cloud-based endpoint management service that provides mobile device management (MDM) and mobile application management (MAM), such as enforcing compliance policies, deploying software, and remote wiping devices. While it improves the security posture of endpoints, it does not ingest signals across email, identities, and cloud apps, nor does it provide alert correlation and automated incident response. Therefore, Intune fails the scenario because it is an administrative tool for managing devices, not a security solution that monitors and responds to cross-domain threats.
- ✓
Microsoft Defender XDR
Why this is correct
Microsoft Defender XDR (formerly Microsoft 365 Defender) is an integrated XDR service that natively aggregates signals from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps. It uses AI and automated response actions to investigate and remediate incidents in a single console, covering email, endpoints, identities, and applications. This exactly matches the requirement to monitor and respond to security incidents across the full Microsoft 365 environment, making it the correct choice.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM and SOAR platform that collects telemetry from diverse sources like Azure, Microsoft 365, and third-party tools, then applies analytics rules to detect and respond to threats. Although it can ingest Microsoft 365 data and orchestrate response playbooks, it is an Azure service requiring custom configuration rather than a built-in Microsoft 365 security solution. The question specifically asks for a solution within Microsoft 365, so Sentinel’s broader, less integrated nature makes it incorrect for this scenario.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 provides advanced threat protection specifically for email, SharePoint, OneDrive, and Teams. It fails this scenario because it lacks the capability to monitor and respond to security incidents on *endpoints* and across the *full range of cloud apps* beyond the core Office 365 suite, which the question explicitly requires. This option is tempting as it addresses a significant portion of the Microsoft 365 environment and would be correct if the scope were limited to advanced protection against threats within those specific Office 365 services.
Go deeper
Related to this question
Learn chapter
Power Apps: Low-Code Application Development
Key term
Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email security service that protects organizations against advanced threats like phishing, malware, and business email compromise by scanning emails, attachments, and links in real time.
Key term
Defender for Cloud
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides unified security management and threat protection across hybrid and multi-cloud environments.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.