Courseiva
mediumMatching

MS-900 Practice Question: Match each Microsoft 365 security feature to its…

Match each Microsoft 365 security feature to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Protects against malicious links and attachments in email

Identity and access management service

Policy-based controls to enforce MFA or block access

Mobile device and application management

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID Protection: Detects and responds to identity-based risks like compromised credentials.

Microsoft Entra ID Protection focuses on identity risks; Microsoft Defender for Office 365 secures email and documents; Microsoft Defender for Endpoint protects devices; Microsoft Information Protection handles data classification and protection. The distractors swap functions between these features.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra ID Protection: Detects and responds to identity-based risks like compromised credentials.

    Why this is correct

    Microsoft Entra ID Protection is a conditional access-aware security feature that analyzes every sign-in attempt against behavioral signals such as impossible travel, anonymous IP addresses, and leaked credentials. It assigns a quantified risk level to users and sign-ins, then triggers automated remediation actions like requiring multi-factor authentication or blocking high-risk sessions. This precisely matches detecting and responding to identity-based risks, not device-level threats.

  • ✓

    Microsoft Defender for Office 365: Protects against malicious threats in email and Office documents.

    Why this is correct

    Microsoft Defender for Office 365 specifically hardens email and collaboration workloads by scanning Exchange Online messages, SharePoint files, and Teams links for phishing, malware, and spoofing. It uses features like Safe Attachments, Safe Links, and anti-phishing policies to detonate suspicious content before it reaches recipients. Thus, it is correctly paired with protecting against malicious threats in email and Office documents.

  • ✓

    Microsoft Defender for Endpoint: Provides advanced threat protection for devices.

    Why this is correct

    Microsoft Defender for Endpoint is a cloud-delivered endpoint security platform that combines next-generation antivirus, endpoint detection and response (EDR), attack surface reduction, and vulnerability management. It continuously monitors device behavior to detect post-breach activities such as lateral movement or credential theft, and enables security teams to investigate and remediate threats. Therefore, it correctly maps to providing advanced threat protection for devices.

  • ✓

    Microsoft Information Protection: Helps classify and protect sensitive data across locations.

    Why this is correct

    Microsoft Information Protection (MIP) focuses on data governance by letting organizations classify sensitive information using customizable labels and apply protection such as encryption, rights management, and access restrictions. These labels and policies can follow data irrespective of whether it is stored in SharePoint, OneDrive, email, or on a laptop, because protection is embedded in the content itself. This aligns with helping classify and protect sensitive data across locations.

  • ✗

    Microsoft Entra ID Protection: Provides advanced threat protection for devices.

    Why it's wrong here

    This pairing is incorrect because Microsoft Entra ID Protection operates on user identities and authentication events, not on device workloads. Device-focused advanced protection, including antivirus scanning and endpoint detection and response, is delivered by Microsoft Defender for Endpoint. Microsoft Entra ID Protection instead evaluates sign-in risk factors to protect identities from compromised credentials and malicious authentication attempts.

  • ✗

    Microsoft Defender for Office 365: Helps classify and protect sensitive data.

    Why it's wrong here

    This is a mismatch because Microsoft Defender for Office 365 is an email and collaboration security solution, not a data classification engine. Sensitive-data classification, labeling, and policy-based protection are the domain of Microsoft Information Protection, which uses double-key encryption and rights management to secure documents and emails wherever they travel. Defender for Office 365 handles phishing, malware, and URL-based threats in messaging workloads.

Go deeper

Related to this question

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.