Courseiva
mediumMatching

SC-200 Practice Question: Match each Microsoft 365 Defender workload to its…

Match each Microsoft 365 Defender workload to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Protects endpoints from cyber threats

Safeguards email and collaboration tools

Detects identity-based attacks using Active Directory signals

Provides visibility and control over cloud apps

Secures multicloud and hybrid environments

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Endpoint: Provides enterprise-grade endpoint security, including antivirus, anti-malware, and advanced threat protection for devices.

Microsoft 365 Defender includes four main workloads: Defender for Endpoint (endpoint security), Defender for Office 365 (email & collaboration), Defender for Identity (on-premises AD security), and Defender for Cloud Apps (cloud app security). Common confusions involve mixing up definitions between these workloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Defender for Endpoint: Provides enterprise-grade endpoint security, including antivirus, anti-malware, and advanced threat protection for devices.

    Why this is correct

    Microsoft Defender for Endpoint is an endpoint detection and response (EDR) solution that collects rich signals from devices via its built-in sensor. It provides next-generation antivirus, attack surface reduction rules, and post-breach investigation capabilities such as threat and vulnerability management. Its core focus is the device itself—Windows, macOS, Linux, Android, and iOS—rather than email infrastructure.

  • ✓

    Microsoft Defender for Office 365: Safeguards email and collaboration tools (Exchange, SharePoint, Teams) against phishing, spam, malware, and other threats.

    Why this is correct

    Microsoft Defender for Office 365 delivers threat protection for messaging and collaboration workloads, including Exchange Online, SharePoint Online, OneDrive, and Teams. Its flagship capabilities include Safe Attachments, Safe Links, anti-phishing policies, and automated investigation of alerts in mailboxes. It specifically addresses email-based attacks like business email compromise (BEC) and ransomware distributed via Office documents.

  • ✓

    Microsoft Defender for Identity: Uses on-premises Active Directory signals to identify, detect, and investigate advanced threats and identity compromises.

    Why this is correct

    Microsoft Defender for Identity leverages on-premises Active Directory signals, including domain controller (DC) audit logs and network traffic, to model user behavior and identify suspicious activities. It detects advanced attack techniques such as pass-the-hash, kerberoasting, and reconnaissance for privilege escalation. The solution uses a machine-learning profile of each user to spot anomalies in logon activities, but it does not replace endpoint or email security.

  • ✓

    Microsoft Defender for Cloud Apps: Acts as a cloud access security broker (CASB) to protect cloud applications and data.

    Why this is correct

    Microsoft Defender for Cloud Apps acts as a cloud access security broker (CASB) that provides visibility, data governance, and threat protection for SaaS and PaaS apps. Its features include cloud discovery, app governance, session-based conditional access controls, and file policy enforcement with quarantine capabilities. It identifies shadow IT risk and can act as a central enforcement point for cloud app usage across the enterprise.

  • ✗

    Microsoft Defender for Endpoint: Safeguards email and collaboration tools (Exchange, SharePoint, Teams) against phishing, spam, malware, and other threats.

    Why it's wrong here

    This description is incorrect because safeguarding email and collaboration tools against phishing, spam, and malware is the function of Microsoft Defender for Office 365, not Microsoft Defender for Endpoint. Defender for Endpoint protects physical and virtual devices with endpoint detection and response, antivirus, and attack surface reduction. The direct assignment of the email scenario to the endpoint solution confuses the workload’s protective layer and scope.

  • ✗

    Microsoft Defender for Office 365: Uses on-premises Active Directory signals to identify, detect, and investigate advanced threats and identity compromises.

    Why it's wrong here

    This description is incorrect because it describes Microsoft Defender for Identity, which uses on-premises Active Directory logs and network traffic to identify identity compromises and advanced threats. Microsoft Defender for Office 365 protects email and collaboration workloads notably with Safe Links, Safe Attachments, and anti-phishing policies, not AD analysis. The answer misattributes an identity-centric workload to an email security solution.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.