MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Your organization has a Microsoft 365 E5 subscription and wants to centrally manage security incidents across identities, endpoints, and cloud apps. Which Microsoft solution provides this capability?
⚠ Common exam trap
MS-900 often tests the distinction between XDR (integrated threat protection across domains) and SIEM (Sentinel, which aggregates logs); candidates may pick Sentinel for centralized incident management, but the question specifies native cross-domain incident management for Microsoft 365 E5.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR
Microsoft Defender XDR (formerly Microsoft 365 Defender) is a unified pre- and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications. It integrates signals from Microsoft Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps into a single portal. This provides centralized security incident management across the specified domains.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID Protection
Why it's wrong here
Entra ID Protection detects and reports identity risk signals such as leaked credentials and anomalous sign-ins, covering only the identity domain. It is tempting because it genuinely surfaces identity incidents, yet endpoints and cloud apps fall outside its scope; Microsoft Defender XDR correlates all three.
- ✗
Microsoft Sentinel
Why it's wrong here
Sentinel is a cloud-native SIEM that ingests logs and builds detections, but it does not natively correlate Microsoft 365 identity, endpoint and cloud-app signals into unified incidents. It is tempting because Sentinel genuinely centralises security data, yet the stem asks for the built-in cross-domain incident capability of Microsoft Defender XDR.
- ✓
Microsoft Defender XDR
Why this is correct
Microsoft Defender XDR correlates signals across identities, endpoints, email and cloud apps into unified incidents, delivering the centralised cross-domain security incident management the E5 subscription requires. It is the Microsoft solution purpose-built for this integrated detection and response capability.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Defender for Endpoint secures and investigates threats on devices only, so it cannot centrally correlate identity and cloud-app incidents. It is tempting because it genuinely feeds endpoint alerts into a unified portal, yet cross-domain incident management across identities, endpoints and cloud apps requires Microsoft Defender XDR.
Go deeper
Related to this question
Learn chapter
Records Management in Microsoft 365
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
Key term
Defender for Endpoint
Microsoft Defender for Endpoint is a cloud-delivered enterprise security solution designed to protect devices from cyber threats using behavioral analysis, machine learning, and automated investigation.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.