SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization wants to use Microsoft Defender XDR to automatically investigate and respond to alerts. You need to ensure that the solution can autonomously remediate confirmed threats on endpoints, such as quarantining files and isolating devices. What should you enable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Endpoint
The correct option is C, Microsoft Defender for Endpoint, because it is the Microsoft Defender XDR workload that provides endpoint detection and response (EDR) capabilities, including automated investigation and response (AIR) that can autonomously quarantine files and isolate devices. Defender for Endpoint integrates with Defender XDR to trigger automated remediation actions on confirmed threats on endpoints. The other options do not provide endpoint remediation: Defender for Identity monitors identity signals, Defender for Cloud Apps governs cloud app usage, and Defender for Office 365 protects email and collaboration workloads, so none of them can isolate devices or quarantine endpoint files.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Identity
Why it's wrong here
Microsoft Defender for Identity is an on-premises Active Directory security product that uses domain controller (DC) traffic and behavior analytics to detect identity-based attacks such as pass-the-hash, Golden Ticket, and Kerberoasting. It does not run on endpoints, lacks the ability to quarantine local files, and cannot isolate a compromised device, so it fails to provide the automated endpoint-centric remediation described in the scenario.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that connects via APIs and reverse-proxy to monitor and control shadow IT, enforce data-loss prevention policies, and assess risk for SaaS applications like Office 365, Google Workspace, and AWS. Because it operates at the application layer and has no visibility into local endpoint processes, files, or network sockets, it cannot perform endpoint-level automated actions such as file quarantine or device isolation.
- ✓
Microsoft Defender for Endpoint
Why this is correct
Microsoft Defender for Endpoint is the correct choice because it is an endpoint detection and response (EDR) solution that continuously monitors devices for malicious activity, triggers automated investigation, and executes remediation playbooks. Its automated response capabilities include quarantining infected or suspicious files, killing malicious processes, and isolating entire devices from the network—exactly the kind of 'auto' response the organization requires. As the endpoint component of Microsoft Defender XDR, it provides the necessary telemetry and action primitives for autonomous threat containment.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 protects email and collaboration platforms—Exchange Online, SharePoint, OneDrive, and Microsoft Teams—by filtering phishing, malware, and malicious URL links before they reach users. While it can automatically purge malicious messages from mailboxes and block delivery, it has no agent on the endpoint and therefore cannot isolate a device, terminate a process, or quarantine a file on the local disk, making it unsuitable for endpoint-focused automated investigation and remediation.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.