MS-900 Describe Microsoft 365 apps and services Practice Question
Which THREE Microsoft 365 services are part of Microsoft Defender XDR (Extended Detection and Response)? (Select three.)
⚠ Common exam trap
Test-takers frequently confuse Microsoft Sentinel (a SIEM) with a component of Defender XDR, but Sentinel is a separate Azure service that ingests logs from Defender XDR rather than being part of the XDR product itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Endpoint
Microsoft Defender XDR (Extended Detection and Response) is a unified security suite that correlates signals across endpoints, identities, and email/collaboration. Microsoft Defender for Endpoint is correct because it provides endpoint detection and response (EDR) capabilities, collecting telemetry from Windows, macOS, Linux, Android, and iOS devices to detect and remediate advanced threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Endpoint
Why this is correct
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution that provides antivirus, attack surface reduction, endpoint detection and response (EDR), and vulnerability management for Windows, macOS, Linux, iOS, and Android devices. It is one of the core signal suppliers to Microsoft Defender XDR, whose unified incident engine correlates device telemetry with identity and email alerts. In this question it is correct because it represents the device-protection workload of Microsoft 365 Defender.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview is the Microsoft 365 compliance and data governance platform, covering information protection, data loss prevention, insider risk management, and records management. These capabilities are designed to meet regulatory and policy requirements rather than to detect active cyberattacks, and Purview is not integrated into Microsoft Defender XDR as a threat-detection workload. It is therefore incorrect here because compliance control is not the same as an XDR pillar such as endpoint, identity, or email protection.
- ✓
Microsoft Defender for Identity
Why this is correct
Microsoft Defender for Identity is a cloud-based security service that monitors on-premises Active Directory traffic, user behavior, and authentication events to detect identity-based attacks like pass-the-hash, golden ticket, and reconnaissance. It is one of the three Microsoft 365 services specifically cited as part of Microsoft Defender XDR, and its alerts are merged into a single incident timeline with Endpoint and Office 365 detections. Thus, it is a correct selection for the question.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM and SOAR platform hosted in Azure, not a Microsoft 365 service. It collects and analyses security telemetry from many sources, including Microsoft 365, Microsoft Entra ID, and third-party products, and can even ingest Defender XDR alerts for centralized enterprise monitoring. That broad aggregation and orchestration role is why it is not one of the three Defender XDR workloads, despite frequently being described alongside them, and it is therefore wrong for this question.
- ✓
Microsoft Defender for Office 365
Why this is correct
Microsoft Defender for Office 365 is a cloud-hosted security service that protects email and collaboration tools such as Exchange Online, SharePoint, OneDrive, and Teams from phishing, malware, spoofing, and business email compromise. Its Safe Attachments and Safe Links features scan content at click-time and in transit, and the service sends rich threat signals into the Microsoft Defender XDR correlation engine. It is correct in this question because email and collaboration protection is the third core workload of Microsoft 365 Defender.
Go deeper
Related to this question
Learn chapter
Microsoft Entra External Identities (B2B)
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.