Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization wants to use Microsoft Defender XDR to automatically investigate and respond to alerts. You need to ensure that the solution can autonomously remediate confirmed threats on endpoints, such as quarantining files and isolating devices. What should you enable?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Endpoint

The correct option is C, Microsoft Defender for Endpoint, because it is the Microsoft Defender XDR workload that provides endpoint detection and response (EDR) capabilities, including automated investigation and response (AIR) that can autonomously quarantine files and isolate devices. Defender for Endpoint integrates with Defender XDR to trigger automated remediation actions on confirmed threats on endpoints. The other options do not provide endpoint remediation: Defender for Identity monitors identity signals, Defender for Cloud Apps governs cloud app usage, and Defender for Office 365 protects email and collaboration workloads, so none of them can isolate devices or quarantine endpoint files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Identity

    Why it's wrong here

    Microsoft Defender for Identity is an on-premises Active Directory security product that uses domain controller (DC) traffic and behavior analytics to detect identity-based attacks such as pass-the-hash, Golden Ticket, and Kerberoasting. It does not run on endpoints, lacks the ability to quarantine local files, and cannot isolate a compromised device, so it fails to provide the automated endpoint-centric remediation described in the scenario.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that connects via APIs and reverse-proxy to monitor and control shadow IT, enforce data-loss prevention policies, and assess risk for SaaS applications like Office 365, Google Workspace, and AWS. Because it operates at the application layer and has no visibility into local endpoint processes, files, or network sockets, it cannot perform endpoint-level automated actions such as file quarantine or device isolation.

  • ✓

    Microsoft Defender for Endpoint

    Why this is correct

    Microsoft Defender for Endpoint is the correct choice because it is an endpoint detection and response (EDR) solution that continuously monitors devices for malicious activity, triggers automated investigation, and executes remediation playbooks. Its automated response capabilities include quarantining infected or suspicious files, killing malicious processes, and isolating entire devices from the network—exactly the kind of 'auto' response the organization requires. As the endpoint component of Microsoft Defender XDR, it provides the necessary telemetry and action primitives for autonomous threat containment.

  • ✗

    Microsoft Defender for Office 365

    Why it's wrong here

    Microsoft Defender for Office 365 protects email and collaboration platforms—Exchange Online, SharePoint, OneDrive, and Microsoft Teams—by filtering phishing, malware, and malicious URL links before they reach users. While it can automatically purge malicious messages from mailboxes and block delivery, it has no agent on the endpoint and therefore cannot isolate a device, terminate a process, or quarantine a file on the local disk, making it unsuitable for endpoint-focused automated investigation and remediation.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.