SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company uses Microsoft Defender for Endpoint on all workstations and Microsoft Defender for Office 365 for email protection. The security operations team wants a single console to see all incidents from both products, automatically investigate and respond to threats across endpoints and email, and integrate with Microsoft Sentinel for advanced hunting. Which Microsoft security solution should they use?
⚠ Common exam trap
Test-takers frequently confuse Microsoft Defender for Cloud (which protects cloud workloads) with Microsoft 365 Defender (which unifies endpoint, email, and identity security), leading them to select the cloud-focused option instead of the cross-workload unified solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft 365 Defender
Microsoft 365 Defender is the correct solution because it provides a unified incident queue that aggregates alerts from Microsoft Defender for Endpoint and Microsoft Defender for Office 365, enabling automated investigation and response (AIR) across endpoints and email. It also natively integrates with Microsoft Sentinel for advanced hunting via the Microsoft 365 Defender connector, allowing the security operations team to correlate signals and perform cross-domain threat hunting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft 365 Defender
Why this is correct
Microsoft 365 Defender is an Extended Detection and Response (XDR) solution that unifies security signals from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. It correlates alerts across these domains into consolidated incidents, providing a comprehensive view of attacks and enabling automated, cross-domain response actions. This integrated approach significantly enhances an organization's ability to detect, investigate, and remediate sophisticated multi-stage threats.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud provides cloud security posture management (CSPM) and cloud workload protection (CWP) across Azure, AWS, and GCP environments. It identifies vulnerabilities, provides security recommendations, and detects threats targeting cloud resources like virtual machines, containers, and databases. While it offers robust cloud security, its primary function is not to unify incident management across on-premises endpoints, user identities, or email systems, which falls under the scope of an XDR solution.
When this WOULD be correct
A company wants to secure its Azure and on-premises servers, containers, and databases, with a focus on cloud security posture management (CSPM) and workload protection, and needs to integrate alerts into Microsoft Sentinel for centralized monitoring.
- ✗
Microsoft Purview Compliance Portal
Why it's wrong here
The Microsoft Purview Compliance Portal is a unified platform designed for data governance, risk management, and regulatory compliance, not for real-time threat detection or incident response. Its capabilities include data classification, eDiscovery, information protection, data loss prevention (DLP), and insider risk management. While crucial for data security and compliance, it does not provide the security operations center (SOC) capabilities needed to manage endpoint or email security incidents.
When this WOULD be correct
A company needs to manage data retention policies, perform eDiscovery, enforce data loss prevention (DLP) rules, and monitor compliance with regulations like GDPR or HIPAA across Microsoft 365 services.
- ✗
Microsoft Entra ID Protection
Why it's wrong here
Microsoft Entra ID Protection focuses exclusively on detecting and remediating identity-based risks within Microsoft Entra ID. It identifies suspicious activities like impossible travel, sign-ins from infected devices, or leaked credentials, and can automatically enforce policies such as requiring multi-factor authentication or blocking access. However, it does not integrate or correlate threat data from endpoints or email systems into a unified security incident view, making it unsuitable for comprehensive XDR.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft 365 DefenderCorrect answer▾
Why this is correct
Microsoft 365 Defender is an Extended Detection and Response (XDR) solution that unifies security signals from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. It correlates alerts across these domains into consolidated incidents, providing a comprehensive view of attacks and enabling automated, cross-domain response actions. This integrated approach significantly enhances an organization's ability to detect, investigate, and remediate sophisticated multi-stage threats.
✗Microsoft Defender for CloudWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Cloud is designed for protecting cloud workloads (e.g., VMs, containers, SQL) across multi-cloud environments, not for unifying endpoint and email incident management or integrating with Microsoft 365 Defender's automated investigation and response.
★ When this WOULD be the correct answer
A company wants to secure its Azure and on-premises servers, containers, and databases, with a focus on cloud security posture management (CSPM) and workload protection, and needs to integrate alerts into Microsoft Sentinel for centralized monitoring.
Why candidates choose this
Candidates may confuse 'Defender for Cloud' with 'Microsoft 365 Defender' due to similar naming, or assume it covers all Microsoft security products, overlooking its specific cloud workload focus.
✗Microsoft Purview Compliance PortalWrong answer — click to see why▾
Why this is wrong here
Microsoft Purview Compliance Portal is focused on data governance, compliance, and risk management, not on unified incident management and automated response for endpoint and email threats.
★ When this WOULD be the correct answer
A company needs to manage data retention policies, perform eDiscovery, enforce data loss prevention (DLP) rules, and monitor compliance with regulations like GDPR or HIPAA across Microsoft 365 services.
Why candidates choose this
Candidates may confuse 'compliance' with security operations, or think that a single portal for all Microsoft 365 security-related tasks includes incident response, but Purview is specifically for compliance and data governance.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
Key term
Microsoft Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email and collaboration security service that protects organizations against malicious threats like phishing, malware, and spam in email messages and Office 365 apps.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.