Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company uses Microsoft 365 and several third-party SaaS apps. The security team wants to detect when a user signs in from a remote location that is significantly far from their typical sign-in location within a very short time, indicating possible account compromise. Which Microsoft security solution should they use?

⚠ Common exam trap

Watch out — candidates often confuse Microsoft Defender for Cloud Apps with Microsoft Defender for Identity, assuming identity protection covers all sign-in anomalies, but MDCA specifically handles cross-cloud app behavioral analytics like impossible travel, while Defender for Identity is limited to on-premises AD and hybrid identity threats.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps (MDCA) provides the 'impossible travel' detection capability, which analyzes sign-in events across both Microsoft 365 and third-party SaaS apps. It uses machine learning to establish a baseline of a user's typical sign-in locations and then alerts when two sign-ins occur from geographically distant locations within a time frame that makes physical travel impossible, indicating a potential account compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Cloud Apps

    Why this is correct

    Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing comprehensive visibility and control over both sanctioned and unsanctioned cloud applications, including Microsoft 365 and third-party SaaS. It excels at detecting anomalous user behavior through advanced analytics, such as impossible travel. This capability specifically identifies suspicious sign-ins originating from geographically disparate locations within an unusually short timeframe, directly addressing the need for detecting such anomalies across various cloud services.

  • Microsoft Defender for Identity

    Why it's wrong here

    Microsoft Defender for Identity is primarily designed to protect hybrid identity environments by monitoring on-premises Active Directory domain controllers and Active Directory Federation Services (AD FS) servers. Its core function is to detect advanced threats, malicious insider actions, and identity-based attacks targeting on-premises identities and infrastructure. While it integrates with Azure AD, its primary focus is not on monitoring or detecting sign-in anomalies across diverse third-party cloud SaaS applications.

  • Microsoft Defender for Office 365

    Why it's wrong here

    Microsoft Defender for Office 365 provides advanced threat protection specifically for an organization's email and collaboration services within the Microsoft 365 suite. It safeguards against sophisticated phishing attacks, malware, spam, and business email compromise across Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams. However, its scope does not extend to monitoring or detecting general sign-in anomalies or impossible travel scenarios across third-party SaaS applications.

  • Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint is an enterprise endpoint security platform focused on protecting devices such as workstations, servers, and mobile devices from cyber threats. It delivers endpoint detection and response (EDR) capabilities, vulnerability management, and attack surface reduction by monitoring device-level activities, processes, and network connections. This solution is not designed to provide visibility into or detect anomalous user sign-in activities across cloud applications or SaaS services.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.