SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A security analyst receives an alert about a suspicious process on a device. The security solution automatically investigates the device, gathers evidence, and determines that a known malware variant was detected. It then presents an action plan to the analyst for remediation. Which Microsoft security solution provides this automated investigation and response capability?
⚠ Common exam trap
Microsoft often tests the distinction between endpoint-focused security (Defender for Endpoint) and cloud/identity/email-focused solutions, so candidates mistakenly choose Defender for Cloud Apps or Defender for Identity when the scenario clearly describes on-device process investigation and automated response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint provides automated investigation and response (AIR) capabilities that automatically investigate alerts, gather evidence, and determine remediation actions. When a suspicious process is detected, Defender for Endpoint's AIR engine analyzes the device, identifies known malware variants, and presents an action plan to the security analyst for approval or execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps (MDCA), formerly Microsoft Cloud App Security (MCAS), functions as a Cloud Access Security Broker (CASB) to provide visibility, control, and protection for cloud applications and data. It helps discover shadow IT, enforce data loss prevention (DLP) policies, and detect anomalous behavior within SaaS applications. However, MDCA's focus is on cloud application usage and data governance, not the real-time monitoring or automated investigation of processes running on an organization's endpoints.
When this WOULD be correct
This option would be correct for a question about detecting and investigating suspicious user behavior or anomalous activities across cloud applications, such as identifying a compromised account using multiple cloud apps.
- ✓
Microsoft Defender for Endpoint
Why this is correct
Microsoft Defender for Endpoint (MDE) is a unified endpoint security platform that utilizes behavioral analytics, machine learning, and cloud intelligence to detect, investigate, and respond to advanced threats on devices. When a security analyst receives an alert about a suspicious process, MDE's Endpoint Detection and Response (EDR) capabilities automatically collect telemetry, analyze process trees, and can initiate automated investigation playbooks to determine the scope and severity of the threat, isolating the device if necessary. This directly addresses the need to investigate a suspicious process on an endpoint.
- ✗
Microsoft Defender for Identity
Why it's wrong here
Microsoft Defender for Identity (MDI) is specifically designed to protect hybrid identity environments by monitoring user behavior and detecting advanced threats targeting Active Directory, both on-premises and in Azure AD. It identifies suspicious activities like credential theft, lateral movement paths, and domain dominance. However, its scope is limited to identity-related threats and does not extend to real-time monitoring or automated investigation of processes running directly on individual endpoints, making it unsuitable for a suspicious process alert.
When this WOULD be correct
A question asks: 'Which Microsoft security solution monitors on-premises Active Directory for suspicious activities like pass-the-hash or DCSync attacks and provides identity-based threat detection?'
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 (MDO) provides comprehensive protection for an organization's email, documents, and collaboration tools within the Microsoft 365 suite. Its primary function is to safeguard against phishing, malware, spam, and business email compromise (BEC) threats by scanning attachments, links, and content. While it can detect malicious files delivered via email, MDO does not possess the capabilities to monitor, investigate, or respond to suspicious processes executing on an endpoint device itself.
When this WOULD be correct
A question describing automated investigation and response for suspicious emails, phishing attempts, or malicious attachments in Exchange Online or SharePoint would make Defender for Office 365 the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Defender for EndpointCorrect answer▾
Why this is correct
Microsoft Defender for Endpoint (MDE) is a unified endpoint security platform that utilizes behavioral analytics, machine learning, and cloud intelligence to detect, investigate, and respond to advanced threats on devices. When a security analyst receives an alert about a suspicious process, MDE's Endpoint Detection and Response (EDR) capabilities automatically collect telemetry, analyze process trees, and can initiate automated investigation playbooks to determine the scope and severity of the threat, isolating the device if necessary. This directly addresses the need to investigate a suspicious process on an endpoint.
✗Microsoft Defender for Cloud AppsWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Cloud Apps focuses on cloud application security, not endpoint device investigation and automated remediation of malware on devices.
★ When this WOULD be the correct answer
This option would be correct for a question about detecting and investigating suspicious user behavior or anomalous activities across cloud applications, such as identifying a compromised account using multiple cloud apps.
Why candidates choose this
Candidates may confuse cloud app security with endpoint security because both involve threat detection and investigation, but Defender for Cloud Apps is specific to cloud services, not device-level processes.
✗Microsoft Defender for IdentityWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Identity focuses on detecting and investigating advanced attacks on on-premises Active Directory, not on automated investigation and response for suspicious processes on devices.
★ When this WOULD be the correct answer
A question asks: 'Which Microsoft security solution monitors on-premises Active Directory for suspicious activities like pass-the-hash or DCSync attacks and provides identity-based threat detection?'
Why candidates choose this
Candidates may confuse identity-based security solutions with endpoint detection and response, or assume that any 'Defender' product includes automated investigation capabilities for all scenarios.
✗Microsoft Defender for Office 365Wrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Office 365 focuses on protecting email and collaboration tools like Exchange Online, SharePoint, and Teams, not on automated investigation and response for endpoint devices.
★ When this WOULD be the correct answer
A question describing automated investigation and response for suspicious emails, phishing attempts, or malicious attachments in Exchange Online or SharePoint would make Defender for Office 365 the correct answer.
Why candidates choose this
Candidates may confuse the automated investigation and response capabilities across different Defender products, assuming all have the same endpoint-focused features.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.