Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A security operations team needs to protect their organization's Windows 10 and Windows 11 devices from advanced persistent threats (APTs), ransomware, and fileless malware. They also require a centralized dashboard to view device security posture, investigate incidents, and perform proactive threat hunting using advanced queries. Which Microsoft security solution should they deploy?

⚠ Common exam trap

It's easy for candidates to confuse the scope of each Defender product, mistakenly selecting Defender for Office 365 or Defender for Identity because they see 'threat protection' in the question, but fail to recognize that the requirement specifically mentions endpoint devices (Windows 10/11) and advanced hunting queries, which are exclusive to Defender for Endpoint.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Endpoint

Microsoft Defender for Endpoint (MDE) is the correct solution because it provides endpoint detection and response (EDR) capabilities specifically designed to protect Windows 10 and Windows 11 devices against advanced persistent threats (APTs), ransomware, and fileless malware. It includes a centralized dashboard (Microsoft 365 Defender portal) for viewing device security posture, investigating incidents, and performing proactive threat hunting using advanced hunting queries based on Kusto Query Language (KQL).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Endpoint

    Why this is correct

    Microsoft Defender for Endpoint is purpose-built for comprehensive endpoint security, offering advanced capabilities like Endpoint Detection and Response (EDR), vulnerability management, and automated investigation and remediation. It provides security operations teams with the tools to proactively hunt for threats across Windows devices, respond to incidents, and maintain a strong security posture against sophisticated cyberattacks, directly addressing the need for device protection and threat hunting.

  • Microsoft Defender for Office 365

    Why it's wrong here

    Microsoft Defender for Office 365 specializes in protecting an organization's email, SharePoint Online, OneDrive for Business, and Microsoft Teams environments. It provides advanced threat protection against phishing, malware, spam, and business email compromise (BEC) attacks targeting collaboration services. However, it does not extend its protection to the endpoint devices themselves, nor does it offer device-level threat hunting or EDR capabilities.

    When this WOULD be correct

    A question asking for a solution to protect an organization's email and Office 365 workloads from phishing, malware, and malicious links, with a centralized dashboard for email security and threat investigation.

  • Microsoft Defender for Identity

    Why it's wrong here

    Microsoft Defender for Identity focuses on detecting identity-based attacks using Active Directory signals, not on endpoint device protection or centralised device security dashboards. It is tempting because its name suggests broad threat coverage, and it would be correct for monitoring on-premises identity compromise, lateral movement, and Kerberos abuse within hybrid environments, but it cannot manage Windows 10/11 device posture, investigate incidents on endpoints, or run advanced hunting queries for fileless malware and APTs.

    When this WOULD be correct

    A question asking for a solution to monitor and protect on-premises Active Directory environments from advanced identity threats like pass-the-hash, golden ticket attacks, or compromised credentials would make Defender for Identity the correct answer.

  • Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing visibility, control, and protection for cloud applications and data. It helps discover shadow IT, monitor user activity across sanctioned and unsanctioned cloud services, enforce data loss prevention (DLP) policies, and identify anomalous behavior. While crucial for cloud security governance, it does not directly secure or manage the endpoint devices from which users access these cloud applications.

    When this WOULD be correct

    This option would be correct in a scenario where an organization needs to discover and control the use of cloud apps, enforce data loss prevention policies for SaaS applications, and detect anomalous behavior in cloud app usage. For example, a question asking for a solution to monitor and secure Shadow IT in Office 365 or other cloud services.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft Defender for EndpointCorrect answer

Why this is correct

Microsoft Defender for Endpoint is purpose-built for comprehensive endpoint security, offering advanced capabilities like Endpoint Detection and Response (EDR), vulnerability management, and automated investigation and remediation. It provides security operations teams with the tools to proactively hunt for threats across Windows devices, respond to incidents, and maintain a strong security posture against sophisticated cyberattacks, directly addressing the need for device protection and threat hunting.

Microsoft Defender for Office 365Wrong answer — click to see why

Why this is wrong here

Microsoft Defender for Office 365 protects email and collaboration tools (Exchange, SharePoint, Teams) from threats like phishing and malware, not Windows 10/11 endpoints from APTs, ransomware, or fileless malware.

★ When this WOULD be the correct answer

A question asking for a solution to protect an organization's email and Office 365 workloads from phishing, malware, and malicious links, with a centralized dashboard for email security and threat investigation.

Why candidates choose this

Candidates may confuse the 'Defender' branding and assume all Defender products provide endpoint protection, or they may think Office 365 protection covers all devices.

Microsoft Defender for IdentityWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Identity focuses on protecting on-premises Active Directory identities and detecting identity-based attacks, not on endpoint device protection against APTs, ransomware, or fileless malware.

★ When this WOULD be the correct answer

A question asking for a solution to monitor and protect on-premises Active Directory environments from advanced identity threats like pass-the-hash, golden ticket attacks, or compromised credentials would make Defender for Identity the correct answer.

Why candidates choose this

Candidates may confuse 'identity' with 'endpoint' security, or assume that protecting identities inherently protects devices, overlooking the specific endpoint-focused requirements in the question.

Microsoft Defender for Cloud AppsWrong answer — click to see why

Why this is wrong here

Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that protects cloud applications, not Windows 10/11 endpoints. It does not provide device-level protection against APTs, ransomware, or fileless malware, nor does it offer a centralized dashboard for device security posture and advanced threat hunting on endpoints.

★ When this WOULD be the correct answer

This option would be correct in a scenario where an organization needs to discover and control the use of cloud apps, enforce data loss prevention policies for SaaS applications, and detect anomalous behavior in cloud app usage. For example, a question asking for a solution to monitor and secure Shadow IT in Office 365 or other cloud services.

Why candidates choose this

Candidates may confuse Defender for Cloud Apps with endpoint protection because both involve security monitoring and threat detection, and the name 'Defender' suggests a broad security suite. They might overlook that this product is specifically for cloud applications, not endpoints.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Go deeper

Related to this question

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.