SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A security operations team needs to protect their organization's Windows 10 and Windows 11 devices from advanced persistent threats (APTs), ransomware, and fileless malware. They also require a centralized dashboard to view device security posture, investigate incidents, and perform proactive threat hunting using advanced queries. Which Microsoft security solution should they deploy?
⚠ Common exam trap
It's easy for candidates to confuse the scope of each Defender product, mistakenly selecting Defender for Office 365 or Defender for Identity because they see 'threat protection' in the question, but fail to recognize that the requirement specifically mentions endpoint devices (Windows 10/11) and advanced hunting queries, which are exclusive to Defender for Endpoint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint (MDE) is the correct solution because it provides endpoint detection and response (EDR) capabilities specifically designed to protect Windows 10 and Windows 11 devices against advanced persistent threats (APTs), ransomware, and fileless malware. It includes a centralized dashboard (Microsoft 365 Defender portal) for viewing device security posture, investigating incidents, and performing proactive threat hunting using advanced hunting queries based on Kusto Query Language (KQL).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Endpoint
Why this is correct
Microsoft Defender for Endpoint is purpose-built for comprehensive endpoint security, offering advanced capabilities like Endpoint Detection and Response (EDR), vulnerability management, and automated investigation and remediation. It provides security operations teams with the tools to proactively hunt for threats across Windows devices, respond to incidents, and maintain a strong security posture against sophisticated cyberattacks, directly addressing the need for device protection and threat hunting.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 specializes in protecting an organization's email, SharePoint Online, OneDrive for Business, and Microsoft Teams environments. It provides advanced threat protection against phishing, malware, spam, and business email compromise (BEC) attacks targeting collaboration services. However, it does not extend its protection to the endpoint devices themselves, nor does it offer device-level threat hunting or EDR capabilities.
When this WOULD be correct
A question asking for a solution to protect an organization's email and Office 365 workloads from phishing, malware, and malicious links, with a centralized dashboard for email security and threat investigation.
- ✗
Microsoft Defender for Identity
Why it's wrong here
Microsoft Defender for Identity focuses on detecting identity-based attacks using Active Directory signals, not on endpoint device protection or centralised device security dashboards. It is tempting because its name suggests broad threat coverage, and it would be correct for monitoring on-premises identity compromise, lateral movement, and Kerberos abuse within hybrid environments, but it cannot manage Windows 10/11 device posture, investigate incidents on endpoints, or run advanced hunting queries for fileless malware and APTs.
When this WOULD be correct
A question asking for a solution to monitor and protect on-premises Active Directory environments from advanced identity threats like pass-the-hash, golden ticket attacks, or compromised credentials would make Defender for Identity the correct answer.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing visibility, control, and protection for cloud applications and data. It helps discover shadow IT, monitor user activity across sanctioned and unsanctioned cloud services, enforce data loss prevention (DLP) policies, and identify anomalous behavior. While crucial for cloud security governance, it does not directly secure or manage the endpoint devices from which users access these cloud applications.
When this WOULD be correct
This option would be correct in a scenario where an organization needs to discover and control the use of cloud apps, enforce data loss prevention policies for SaaS applications, and detect anomalous behavior in cloud app usage. For example, a question asking for a solution to monitor and secure Shadow IT in Office 365 or other cloud services.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Defender for EndpointCorrect answer▾
Why this is correct
Microsoft Defender for Endpoint is purpose-built for comprehensive endpoint security, offering advanced capabilities like Endpoint Detection and Response (EDR), vulnerability management, and automated investigation and remediation. It provides security operations teams with the tools to proactively hunt for threats across Windows devices, respond to incidents, and maintain a strong security posture against sophisticated cyberattacks, directly addressing the need for device protection and threat hunting.
✗Microsoft Defender for Office 365Wrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Office 365 protects email and collaboration tools (Exchange, SharePoint, Teams) from threats like phishing and malware, not Windows 10/11 endpoints from APTs, ransomware, or fileless malware.
★ When this WOULD be the correct answer
A question asking for a solution to protect an organization's email and Office 365 workloads from phishing, malware, and malicious links, with a centralized dashboard for email security and threat investigation.
Why candidates choose this
Candidates may confuse the 'Defender' branding and assume all Defender products provide endpoint protection, or they may think Office 365 protection covers all devices.
✗Microsoft Defender for IdentityWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Identity focuses on protecting on-premises Active Directory identities and detecting identity-based attacks, not on endpoint device protection against APTs, ransomware, or fileless malware.
★ When this WOULD be the correct answer
A question asking for a solution to monitor and protect on-premises Active Directory environments from advanced identity threats like pass-the-hash, golden ticket attacks, or compromised credentials would make Defender for Identity the correct answer.
Why candidates choose this
Candidates may confuse 'identity' with 'endpoint' security, or assume that protecting identities inherently protects devices, overlooking the specific endpoint-focused requirements in the question.
✗Microsoft Defender for Cloud AppsWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that protects cloud applications, not Windows 10/11 endpoints. It does not provide device-level protection against APTs, ransomware, or fileless malware, nor does it offer a centralized dashboard for device security posture and advanced threat hunting on endpoints.
★ When this WOULD be the correct answer
This option would be correct in a scenario where an organization needs to discover and control the use of cloud apps, enforce data loss prevention policies for SaaS applications, and detect anomalous behavior in cloud app usage. For example, a question asking for a solution to monitor and secure Shadow IT in Office 365 or other cloud services.
Why candidates choose this
Candidates may confuse Defender for Cloud Apps with endpoint protection because both involve security monitoring and threat detection, and the name 'Defender' suggests a broad security suite. They might overlook that this product is specifically for cloud applications, not endpoints.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint is a cloud-delivered enterprise-grade security platform that protects devices, servers, and networks from advanced cyber threats by combining antivirus, endpoint detection and response, and automated investigation and remediation.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.