Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A security analyst needs to investigate a potential malware outbreak that started on an on-premises Windows server several days ago. They want to trace the attack timeline, see which files were modified, and understand how the attacker moved laterally across the network. Which Microsoft solution provides advanced endpoint detection and response (EDR) for on-premises servers?

⚠ Common exam trap

It's easy for candidates to confuse Microsoft Defender for Cloud's 'servers' workload protection with the actual EDR engine, not realizing that Defender for Cloud merely enables MDE on servers but does not replace its dedicated endpoint detection and response capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Endpoint

Microsoft Defender for Endpoint (MDE) provides advanced endpoint detection and response (EDR) capabilities, including behavioral-based detection, automated investigation, and threat analytics. For on-premises Windows servers, MDE can be deployed via Microsoft Defender for Cloud (formerly Azure Security Center) or directly, enabling full attack timeline reconstruction, file modification tracking, and lateral movement path analysis through its rich telemetry and incident graph.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud primarily offers Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) across multi-cloud and hybrid environments. While it provides security recommendations and threat protection for various workloads, including servers, its core function is not a dedicated Endpoint Detection and Response (EDR) solution for deep, real-time investigation of malware on individual on-premises endpoints. It focuses more on identifying vulnerabilities, misconfigurations, and providing broad workload protection rather than granular EDR incident response capabilities for malware analysis.

  • Microsoft Defender for Endpoint

    Why this is correct

    Microsoft Defender for Endpoint is the dedicated Endpoint Detection and Response (EDR) solution designed to protect, detect, investigate, and respond to advanced threats on endpoints, including on-premises servers. It provides comprehensive capabilities such as real-time monitoring, behavioral analytics, automated investigation and remediation, and advanced threat hunting tools. This platform is specifically engineered to identify and analyze malware, track its activities, and facilitate a security analyst's investigation into potential compromises directly on the affected machines.

  • Microsoft Defender for Office 365

    Why it's wrong here

    Microsoft Defender for Office 365 is a specialized security service focused on protecting an organization's email, documents, and collaboration tools within the Microsoft 365 ecosystem. It provides advanced threat protection against phishing, spam, malware, and business email compromise (BEC) attacks targeting user mailboxes and shared files. However, it does not offer Endpoint Detection and Response (EDR) capabilities for investigating malware directly on operating systems of on-premises servers or other endpoints, as its scope is limited to the M365 productivity suite.

  • Microsoft Defender for Identity

    Why it's wrong here

    Microsoft Defender for Identity is a cloud-based security solution that leverages on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions. It focuses on protecting user identities and credentials by monitoring for suspicious activities like lateral movement, privilege escalation, and credential theft. While crucial for overall security, it does not provide the endpoint-level visibility, file modification tracking, or process monitoring necessary for a security analyst to directly investigate potential malware on a server's operating system.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.