SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A manufacturing company experiences repeated ransomware attacks targeting their on-premises file servers. They have Microsoft 365 E5 and want to implement a solution to detect and automatically respond to such threats across hybrid environments. What should they deploy?
⚠ Common exam trap
Candidates often confuse Defender for Identity (on-premises AD protection) with Defender for Office 365 (email protection) or Defender for Cloud Apps (SaaS shadow IT), failing to recognize that the question explicitly mentions on-premises file servers and hybrid environments, which require identity-based detection and response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Identity
Microsoft Defender for Identity is the correct solution because it uses on-premises Active Directory signals to detect, investigate, and respond to advanced threats like ransomware targeting hybrid environments. It integrates with Microsoft 365 Defender to automatically initiate response actions (e.g., disabling compromised accounts) when suspicious lateral movement or credential theft is detected, directly addressing the scenario of repeated ransomware attacks on on-premises file servers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Identity
Why this is correct
Microsoft Defender for Identity is specifically designed to monitor on-premises Active Directory (AD) environments for suspicious activities and advanced threats. Ransomware attacks frequently involve compromising AD credentials for lateral movement and privilege escalation. Defender for Identity detects these attacker behaviors, such as Pass-the-Hash, Golden Ticket attacks, or unusual account access patterns, by analyzing network traffic and AD logs, providing crucial early detection against sophisticated ransomware campaigns targeting an organization's core identity infrastructure.
- ✗
Microsoft Purview Communication Compliance
Why it's wrong here
Microsoft Purview Communication Compliance is a solution focused on regulatory compliance and risk management by monitoring internal and external communications within an organization. It analyzes messages in platforms like Microsoft Teams, Exchange Online, and Yammer to detect policy violations, such as harassment, sensitive data leakage, or insider trading. This service is not designed for real-time threat detection or protection against infrastructure-level security threats like ransomware attacks on servers.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 provides advanced threat protection specifically tailored for Microsoft 365 services, including email (Exchange Online), SharePoint Online, OneDrive for Business, and Microsoft Teams. It safeguards against phishing, malware, and other sophisticated email-borne threats through features like Safe Attachments and Safe Links. While critical for protecting cloud productivity tools, it does not extend its protective capabilities to on-premises file servers or detect ransomware activity directly impacting local network infrastructure.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing comprehensive visibility, control, and protection for cloud applications and services. Its primary role involves identifying shadow IT, enforcing data loss prevention (DLP) policies, and detecting anomalous behavior within sanctioned cloud apps like Office 365, Salesforce, or Box. Although it can integrate with on-premises components, its core focus is securing cloud application usage and data, not directly monitoring or protecting on-premises server infrastructure from ransomware attacks.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Defender for Identity
Defender for Identity is a cloud-based security solution that detects, investigates, and responds to advanced identity threats targeting on-premises Active Directory and cloud identities.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.