Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company uses Microsoft 365 E5 and wants to protect against advanced cyber threats. Which THREE capabilities of Microsoft Defender XDR should they implement?

⚠ Common exam trap

It's easy for candidates to confuse Microsoft Sentinel (a SIEM) with an XDR component, but Sentinel is a separate analytics service that ingests data from XDR solutions rather than being a core part of Microsoft Defender XDR's integrated threat protection suite.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Office 365

Microsoft Defender XDR is the unified extended detection and response suite that natively correlates signals across endpoints, email and collaboration, identities, and cloud apps, so the three correct components here are Defender for Office 365 (B), Defender for Cloud Apps (D), and Defender for Endpoint (E). Defender for Office 365 (B) is correct because it protects Exchange Online, Teams, and SharePoint/OneDrive against phishing, business email compromise, malicious attachments/URLs, and zero-day threats via Safe Attachments, Safe Links, and automated investigation and response. Defender for Cloud Apps (D) is correct because it is the cloud access security broker (CASB) that discovers shadow IT, enforces session and conditional access policies, and detects anomalous behavior across SaaS apps, feeding those alerts into the XDR incident queue. Defender for Endpoint (E) is correct because it delivers endpoint detection and response (EDR), attack surface reduction, next-generation antivirus, and automated investigation/remediation on Windows, macOS, Linux, iOS, and Android devices. Microsoft Intune (A) is not part of Defender XDR; it is a separate endpoint management/MDM service, and Microsoft Sentinel (C) is a standalone cloud-native SIEM/SOAR platform that can ingest Defender XDR incidents but is not itself one of the Defender XDR workloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is primarily a Unified Endpoint Management (UEM) solution, focusing on Mobile Device Management (MDM) and Mobile Application Management (MAM). Its core function is to manage and secure devices and applications by enforcing policies, deploying software, and ensuring compliance. While crucial for endpoint security posture, Intune does not provide the advanced threat detection, investigation, and automated response capabilities that define an Extended Detection and Response (XDR) solution.

  • ✓

    Microsoft Defender for Office 365

    Why this is correct

    This service is a core component of Microsoft 365 Defender, providing robust protection against sophisticated threats targeting email and collaboration tools. It safeguards against phishing, business email compromise (BEC), malware, and other advanced attacks across Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams. Its integrated detection and response capabilities are essential for protecting user productivity and data within the Microsoft 365 ecosystem.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platform. While it ingests security data from various sources, including Microsoft 365 Defender components, to provide centralized visibility, advanced analytics, and automated responses across the entire enterprise, it is a complementary solution for security operations, not an XDR component itself. XDR focuses on deep, integrated protection within specific domains, whereas SIEM aggregates and correlates data across all domains.

  • ✓

    Microsoft Defender for Cloud Apps

    Why this is correct

    Microsoft Defender for Cloud Apps operates as a Cloud Access Security Broker (CASB), offering visibility into cloud applications, identifying shadow IT, and enforcing data loss prevention (DLP) policies. It helps secure access to cloud services and protects sensitive data residing within them. Although it contributes valuable security signals and policy enforcement, it is a specialized CASB solution and not considered a core detection and response component of the integrated Microsoft 365 Defender XDR platform.

  • ✓

    Microsoft Defender for Endpoint

    Why this is correct

    Microsoft Defender for Endpoint is a foundational element of Microsoft's XDR strategy, delivering comprehensive Endpoint Detection and Response (EDR) capabilities. It provides advanced threat protection, post-breach detection, automated investigation, and response for a wide range of endpoints, including workstations, servers, and mobile devices. Its deep visibility into endpoint activity and ability to remediate threats are critical for identifying and mitigating sophisticated attacks across an organization's device estate.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.