Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A security analyst receives an alert about a suspicious process on a device. The security solution automatically investigates the device, gathers evidence, and determines that a known malware variant was detected. It then presents an action plan to the analyst for remediation. Which Microsoft security solution provides this automated investigation and response capability?

⚠ Common exam trap

Microsoft often tests the distinction between endpoint-focused security (Defender for Endpoint) and cloud/identity/email-focused solutions, so candidates mistakenly choose Defender for Cloud Apps or Defender for Identity when the scenario clearly describes on-device process investigation and automated response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Endpoint

Microsoft Defender for Endpoint provides automated investigation and response (AIR) capabilities that automatically investigate alerts, gather evidence, and determine remediation actions. When a suspicious process is detected, Defender for Endpoint's AIR engine analyzes the device, identifies known malware variants, and presents an action plan to the security analyst for approval or execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps (MDCA), formerly Microsoft Cloud App Security (MCAS), functions as a Cloud Access Security Broker (CASB) to provide visibility, control, and protection for cloud applications and data. It helps discover shadow IT, enforce data loss prevention (DLP) policies, and detect anomalous behavior within SaaS applications. However, MDCA's focus is on cloud application usage and data governance, not the real-time monitoring or automated investigation of processes running on an organization's endpoints.

    When this WOULD be correct

    This option would be correct for a question about detecting and investigating suspicious user behavior or anomalous activities across cloud applications, such as identifying a compromised account using multiple cloud apps.

  • Microsoft Defender for Endpoint

    Why this is correct

    Microsoft Defender for Endpoint (MDE) is a unified endpoint security platform that utilizes behavioral analytics, machine learning, and cloud intelligence to detect, investigate, and respond to advanced threats on devices. When a security analyst receives an alert about a suspicious process, MDE's Endpoint Detection and Response (EDR) capabilities automatically collect telemetry, analyze process trees, and can initiate automated investigation playbooks to determine the scope and severity of the threat, isolating the device if necessary. This directly addresses the need to investigate a suspicious process on an endpoint.

  • Microsoft Defender for Identity

    Why it's wrong here

    Microsoft Defender for Identity (MDI) is specifically designed to protect hybrid identity environments by monitoring user behavior and detecting advanced threats targeting Active Directory, both on-premises and in Azure AD. It identifies suspicious activities like credential theft, lateral movement paths, and domain dominance. However, its scope is limited to identity-related threats and does not extend to real-time monitoring or automated investigation of processes running directly on individual endpoints, making it unsuitable for a suspicious process alert.

    When this WOULD be correct

    A question asks: 'Which Microsoft security solution monitors on-premises Active Directory for suspicious activities like pass-the-hash or DCSync attacks and provides identity-based threat detection?'

  • Microsoft Defender for Office 365

    Why it's wrong here

    Microsoft Defender for Office 365 (MDO) provides comprehensive protection for an organization's email, documents, and collaboration tools within the Microsoft 365 suite. Its primary function is to safeguard against phishing, malware, spam, and business email compromise (BEC) threats by scanning attachments, links, and content. While it can detect malicious files delivered via email, MDO does not possess the capabilities to monitor, investigate, or respond to suspicious processes executing on an endpoint device itself.

    When this WOULD be correct

    A question describing automated investigation and response for suspicious emails, phishing attempts, or malicious attachments in Exchange Online or SharePoint would make Defender for Office 365 the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft Defender for EndpointCorrect answer

Why this is correct

Microsoft Defender for Endpoint (MDE) is a unified endpoint security platform that utilizes behavioral analytics, machine learning, and cloud intelligence to detect, investigate, and respond to advanced threats on devices. When a security analyst receives an alert about a suspicious process, MDE's Endpoint Detection and Response (EDR) capabilities automatically collect telemetry, analyze process trees, and can initiate automated investigation playbooks to determine the scope and severity of the threat, isolating the device if necessary. This directly addresses the need to investigate a suspicious process on an endpoint.

Microsoft Defender for Cloud AppsWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Cloud Apps focuses on cloud application security, not endpoint device investigation and automated remediation of malware on devices.

★ When this WOULD be the correct answer

This option would be correct for a question about detecting and investigating suspicious user behavior or anomalous activities across cloud applications, such as identifying a compromised account using multiple cloud apps.

Why candidates choose this

Candidates may confuse cloud app security with endpoint security because both involve threat detection and investigation, but Defender for Cloud Apps is specific to cloud services, not device-level processes.

Microsoft Defender for IdentityWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Identity focuses on detecting and investigating advanced attacks on on-premises Active Directory, not on automated investigation and response for suspicious processes on devices.

★ When this WOULD be the correct answer

A question asks: 'Which Microsoft security solution monitors on-premises Active Directory for suspicious activities like pass-the-hash or DCSync attacks and provides identity-based threat detection?'

Why candidates choose this

Candidates may confuse identity-based security solutions with endpoint detection and response, or assume that any 'Defender' product includes automated investigation capabilities for all scenarios.

Microsoft Defender for Office 365Wrong answer — click to see why

Why this is wrong here

Microsoft Defender for Office 365 focuses on protecting email and collaboration tools like Exchange Online, SharePoint, and Teams, not on automated investigation and response for endpoint devices.

★ When this WOULD be the correct answer

A question describing automated investigation and response for suspicious emails, phishing attempts, or malicious attachments in Exchange Online or SharePoint would make Defender for Office 365 the correct answer.

Why candidates choose this

Candidates may confuse the automated investigation and response capabilities across different Defender products, assuming all have the same endpoint-focused features.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.