SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company uses Microsoft 365 and Azure. They want a unified security solution that provides threat protection across email, endpoints, identities, and cloud apps, with automated investigation and response capabilities. Which Microsoft solution should they use?
⚠ Common exam trap
Candidates often confuse Microsoft Defender for Cloud (a CSPM/CWPP tool for cloud workloads) with Microsoft 365 Defender (a unified XDR solution for the Microsoft 365 ecosystem), or they mistakenly think Microsoft Sentinel (a SIEM) provides the same built-in, cross-domain automated investigation and response as Microsoft 365 Defender.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft 365 Defender
Microsoft 365 Defender is a unified pre- and post-breach enterprise defense suite that coordinates detection, prevention, investigation, and response across email, endpoints, identities, and cloud apps. It provides automated investigation and response (AIR) capabilities through its integrated components (e.g., Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps), making it the correct choice for the described requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud primarily functions as a Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP). It focuses on securing Azure, multi-cloud, and hybrid environments by identifying misconfigurations, vulnerabilities, and threats across infrastructure, data, and applications. While crucial for cloud infrastructure security, it does not offer the integrated Extended Detection and Response (XDR) capabilities specifically designed to correlate signals across Microsoft 365 services like email, endpoints, and identities.
- ✓
Microsoft 365 Defender
Why this is correct
Microsoft 365 Defender is the correct solution as it provides a unified Extended Detection and Response (XDR) experience specifically tailored for the Microsoft 365 ecosystem. It automatically collects, correlates, and analyzes security signals from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. This integrated approach enables cross-domain threat protection, automated investigation, and remediation across email, endpoints, identities, and cloud applications, offering a holistic view of an organization's security posture within Microsoft 365.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration automated response (SOAR) solution. It aggregates security data from many sources but is not specifically designed as a unified XDR for Microsoft 365.
- ✗
Microsoft Entra ID Protection
Why it's wrong here
Microsoft Entra ID Protection is a specialized capability within Microsoft Entra ID (formerly Azure Active Directory) focused exclusively on identity-based risk detection and remediation. It identifies potential vulnerabilities affecting user identities, such as leaked credentials, suspicious sign-ins, and anomalous user behavior, and can automate responses like requiring multi-factor authentication or password resets. While critical for identity security, it operates at a single domain level and does not provide the broad, cross-domain Extended Detection and Response (XDR) coverage needed for email, endpoints, and cloud applications across the entire Microsoft 365 suite.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Defender for Cloud Apps
Defender for Cloud Apps is a Microsoft cloud access security broker (CASB) that helps you discover, protect, and govern your cloud applications and data across multiple cloud environments.
Key term
Defender for Endpoint
Microsoft Defender for Endpoint is a cloud-delivered enterprise security solution designed to protect devices from cyber threats using behavioral analysis, machine learning, and automated investigation.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.