SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company wants to improve its security awareness program by periodically sending simulated phishing emails to employees to test their ability to identify malicious messages. The results should be tracked in a dashboard that shows which employees clicked the links. Which Microsoft 365 Defender capability should they use?
⚠ Common exam trap
Many exam-takers confuse the broader Microsoft Defender for Office 365 (which includes anti-phishing policies) with the specific Attack Simulation Training feature, assuming the entire suite is needed for simulation, when in fact the simulation tool is a discrete component with its own dashboard and configuration portal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attack Simulation Training
Attack Simulation Simulation Training is the correct answer because it is the specific Microsoft 365 Defender capability designed to create and launch simulated phishing campaigns, track employee interactions (e.g., clicks on malicious links), and report results in a dashboard. This feature is part of Microsoft Defender for Office 365 but is a distinct workload focused on security awareness training and measurement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Attack Simulation Training
Why this is correct
Attack Simulation Training, integrated within Microsoft 365 Defender, is specifically engineered to create and manage realistic simulated cyberattacks, such as phishing, credential harvest, and malware attachment campaigns. This service allows organizations to proactively assess employee susceptibility to various social engineering techniques and automatically delivers targeted training to those who fall for the simulations. Its primary purpose is to strengthen the human firewall by improving security awareness and behavior through practical, measured experience.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 provides advanced protection against sophisticated email and collaboration threats, including phishing, business email compromise (BEC), and malware. Key features like Safe Attachments, Safe Links, and anti-phishing policies actively scan and neutralize malicious content before it reaches users' inboxes or when they click on links. While it defends against real phishing attempts, it does not offer the functionality to create and manage simulated phishing campaigns for employee training purposes.
When this WOULD be correct
A question asking which Microsoft 365 Defender capability protects against phishing, malware, and spam in email and collaboration tools, without mentioning simulated phishing campaigns or employee training tracking.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing comprehensive visibility, control, and protection for data across an organization's cloud applications. Its primary capabilities include discovering shadow IT, identifying sensitive information, enforcing data loss prevention policies, and detecting anomalous user behavior within cloud services. This solution focuses on securing cloud application usage and data governance, not on conducting user awareness training simulations.
When this WOULD be correct
A company wants to discover shadow IT usage and control access to sanctioned and unsanctioned cloud apps, with policies to block risky apps and enforce data loss prevention.
- ✗
Microsoft 365 Defender Incident Response
Why it's wrong here
Microsoft 365 Defender Incident Response is a unified XDR (Extended Detection and Response) capability designed to automatically detect, investigate, and respond to real security incidents across endpoints, identities, email, and cloud apps. It correlates alerts from various Defender services into cohesive incidents, enabling security teams to quickly understand the scope of an attack and initiate remediation actions. This feature is crucial for managing actual threats and breaches, rather than for simulating attacks to test user awareness.
When this WOULD be correct
This option would be correct if the question asked: 'Which Microsoft 365 Defender capability is used to investigate and respond to a confirmed phishing attack that has already compromised user accounts?'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Attack Simulation TrainingCorrect answer▾
Why this is correct
Attack Simulation Training, integrated within Microsoft 365 Defender, is specifically engineered to create and manage realistic simulated cyberattacks, such as phishing, credential harvest, and malware attachment campaigns. This service allows organizations to proactively assess employee susceptibility to various social engineering techniques and automatically delivers targeted training to those who fall for the simulations. Its primary purpose is to strengthen the human firewall by improving security awareness and behavior through practical, measured experience.
✗Microsoft Defender for Office 365Wrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Office 365 provides email security features like anti-phishing and anti-spam, but it does not include the ability to create and manage simulated phishing campaigns with employee tracking dashboards. That specific functionality is part of Attack Simulation Training.
★ When this WOULD be the correct answer
A question asking which Microsoft 365 Defender capability protects against phishing, malware, and spam in email and collaboration tools, without mentioning simulated phishing campaigns or employee training tracking.
Why candidates choose this
Candidates may confuse the general email protection capabilities of Defender for Office 365 with the specific simulated phishing and training features of Attack Simulation Training, assuming that any phishing-related task falls under Defender for Office 365.
✗Microsoft Defender for Cloud AppsWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Cloud Apps is a CASB for discovering and controlling cloud app usage, not for simulating phishing attacks or tracking employee click rates in a security awareness program.
★ When this WOULD be the correct answer
A company wants to discover shadow IT usage and control access to sanctioned and unsanctioned cloud apps, with policies to block risky apps and enforce data loss prevention.
Why candidates choose this
Candidates may confuse cloud app security with email security, thinking Defender for Cloud Apps includes phishing simulation because it deals with cloud-based threats.
✗Microsoft 365 Defender Incident ResponseWrong answer — click to see why▾
Why this is wrong here
Microsoft 365 Defender Incident Response is focused on managing and responding to security incidents after they occur, not on proactively simulating phishing attacks to train employees.
★ When this WOULD be the correct answer
This option would be correct if the question asked: 'Which Microsoft 365 Defender capability is used to investigate and respond to a confirmed phishing attack that has already compromised user accounts?'
Why candidates choose this
Candidates may confuse incident response with attack simulation because both involve handling phishing threats, but incident response is reactive while simulation is proactive training.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.