Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A manufacturing company experiences repeated ransomware attacks targeting their on-premises file servers. They have Microsoft 365 E5 and want to implement a solution to detect and automatically respond to such threats across hybrid environments. What should they deploy?

⚠ Common exam trap

Candidates often confuse Defender for Identity (on-premises AD protection) with Defender for Office 365 (email protection) or Defender for Cloud Apps (SaaS shadow IT), failing to recognize that the question explicitly mentions on-premises file servers and hybrid environments, which require identity-based detection and response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Identity

Microsoft Defender for Identity is the correct solution because it uses on-premises Active Directory signals to detect, investigate, and respond to advanced threats like ransomware targeting hybrid environments. It integrates with Microsoft 365 Defender to automatically initiate response actions (e.g., disabling compromised accounts) when suspicious lateral movement or credential theft is detected, directly addressing the scenario of repeated ransomware attacks on on-premises file servers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Identity

    Why this is correct

    Microsoft Defender for Identity is specifically designed to monitor on-premises Active Directory (AD) environments for suspicious activities and advanced threats. Ransomware attacks frequently involve compromising AD credentials for lateral movement and privilege escalation. Defender for Identity detects these attacker behaviors, such as Pass-the-Hash, Golden Ticket attacks, or unusual account access patterns, by analyzing network traffic and AD logs, providing crucial early detection against sophisticated ransomware campaigns targeting an organization's core identity infrastructure.

  • Microsoft Purview Communication Compliance

    Why it's wrong here

    Microsoft Purview Communication Compliance is a solution focused on regulatory compliance and risk management by monitoring internal and external communications within an organization. It analyzes messages in platforms like Microsoft Teams, Exchange Online, and Yammer to detect policy violations, such as harassment, sensitive data leakage, or insider trading. This service is not designed for real-time threat detection or protection against infrastructure-level security threats like ransomware attacks on servers.

  • Microsoft Defender for Office 365

    Why it's wrong here

    Microsoft Defender for Office 365 provides advanced threat protection specifically tailored for Microsoft 365 services, including email (Exchange Online), SharePoint Online, OneDrive for Business, and Microsoft Teams. It safeguards against phishing, malware, and other sophisticated email-borne threats through features like Safe Attachments and Safe Links. While critical for protecting cloud productivity tools, it does not extend its protective capabilities to on-premises file servers or detect ransomware activity directly impacting local network infrastructure.

  • Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing comprehensive visibility, control, and protection for cloud applications and services. Its primary role involves identifying shadow IT, enforcing data loss prevention (DLP) policies, and detecting anomalous behavior within sanctioned cloud apps like Office 365, Salesforce, or Box. Although it can integrate with on-premises components, its core focus is securing cloud application usage and data, not directly monitoring or protecting on-premises server infrastructure from ransomware attacks.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.