Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company wants to protect against ransomware by detecting and blocking malicious files in email attachments. Which Microsoft security solution should be used?

⚠ Common exam trap

A common mix-up: candidates confuse endpoint protection (Defender for Endpoint) with email security, forgetting that Defender for Office 365 is the dedicated solution for email-borne threats like malicious attachments in ransomware attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Office 365

Microsoft Defender for Office 365 includes Safe Attachments and Safe Links features that scan email attachments in real-time using detonation chambers and machine learning to detect and block ransomware and other malicious files. This solution is specifically designed to protect Exchange Online and SharePoint Online from threats delivered via email, making it the correct choice for blocking malicious attachments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Identity

    Why it's wrong here

    Microsoft Defender for Identity is specifically designed to protect hybrid identity environments by monitoring Active Directory domain controllers and other identity infrastructure for suspicious activities and advanced threats. It excels at detecting identity-based attacks such as credential theft, lateral movement, and privilege escalation within an organization's on-premises and cloud identity systems. While crucial for overall security, it does not provide direct protection against ransomware delivered through email attachments or malicious links within email messages, as its scope is identity and infrastructure, not email content scanning.

  • Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing comprehensive visibility into cloud applications and services, identifying shadow IT, and enforcing data loss prevention policies across sanctioned apps. It helps discover and control the use of cloud applications, protect sensitive information stored within them, and detect anomalous user behavior across various SaaS platforms. However, its primary role is not to scan incoming email for ransomware or malware before it reaches user inboxes, making it unsuitable for direct email-borne threat protection at the gateway level.

  • Microsoft Defender for Office 365

    Why this is correct

    Microsoft Defender for Office 365 is the dedicated security service engineered to protect an organization's email, collaboration, and productivity tools within Microsoft 365 from advanced threats. It employs robust capabilities like Safe Attachments, which detonates suspicious attachments in a sandbox environment, and Safe Links, which rewrites and scans URLs at the time of click. This comprehensive protection specifically targets ransomware, phishing, business email compromise, and other sophisticated malware delivered via email or Microsoft Teams, making it the correct solution for detecting email-borne ransomware.

  • Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint provides comprehensive endpoint protection, including next-generation antivirus, endpoint detection and response (EDR), automated investigation and remediation, and threat vulnerability management for devices. It monitors device behavior, detects malicious activities, and helps contain and remediate threats that execute on workstations, servers, or mobile devices. While critical for preventing ransomware execution on an endpoint should it bypass other defenses, it does not directly scan or block malicious emails at the mail gateway level before they reach a user's inbox, which is the initial vector for many ransomware attacks.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.