Courseiva

Microsoft Defender for Cloud for Hybrid Environments

Which TWO of the following are capabilities of Microsoft Defender for Cloud? (Choose two.)

⚠ Common exam trap

It's easy for candidates to confuse the integrated capabilities of Microsoft Defender for Cloud with those of other Microsoft security products (Defender for Office 365, Entra ID Protection, Defender for Endpoint), leading them to select options that are valid security features but belong to separate services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Workload Protection (CWP)

Microsoft Defender for Cloud is a Cloud Security Posture Management (CSPM) and cloud workload protection platform, so option E is correct: it continuously assesses Azure, AWS, GCP, and on-premises resources against security benchmarks (e.g., Microsoft Cloud Security Benchmark) and surfaces secure score recommendations. Option D is also correct: Defender for Cloud provides Cloud Workload Protection (CWP) through plans such as Defender for Servers, Containers, Storage, SQL, App Service, and Key Vault, delivering threat detection and advanced protection for those workloads. Option A is not correct because email security is handled by Microsoft Defender for Office 365 (part of Microsoft 365 Defender), not Defender for Cloud. Option B is not correct because identity protection is provided by Microsoft Entra ID Protection and Defender for Identity, not Defender for Cloud. Option C is not correct because endpoint detection and response (EDR) is delivered by Microsoft Defender for Endpoint, which Defender for Cloud can integrate with but does not itself provide as a native capability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Email security

    Why it's wrong here

    Email security is delivered by Microsoft Defender for Office 365, which inspects Exchange Online mail flow; Defender for Cloud assesses and protects cloud workloads and infrastructure. It is tempting because Defender for Cloud's secure score and recommendations span Microsoft 365 services, but email filtering itself sits outside its workload protection scope.

  • ✗

    Identity protection

    Why it's wrong here

    Identity protection is a Microsoft Entra ID capability, detecting risky users and sign-ins; Defender for Cloud covers infrastructure and platform workloads rather than directory identities. It is tempting because Defender for Cloud's recommendations reference identity configuration, but the risk-detection engine itself resides in Microsoft Entra ID.

  • ✗

    Endpoint detection and response (EDR)

    Why it's wrong here

    EDR is provided by Microsoft Defender for Endpoint, which deploys sensors on devices; Defender for Cloud instead surfaces posture recommendations and workload protection for servers, containers, databases and storage. It is tempting because Defender for Cloud can onboard servers, yet the endpoint detection capability itself belongs to Defender for Endpoint.

  • ✓

    Cloud Workload Protection (CWP)

    Why this is correct

    Cloud Workload Protection delivers runtime threat detection for VMs, containers and databases, satisfying the stem's requirement for a Defender for Cloud capability. It is the workload-level defence pillar, distinct from posture management, generating alerts for active attacks rather than configuration weaknesses.

  • ✓

    Cloud Security Posture Management (CSPM)

    Why this is correct

    Cloud Security Posture Management continuously assesses resources against benchmarks and surfaces misconfigurations, satisfying the stem's requirement for a Defender for Cloud capability. It is the posture pillar, distinct from workload protection, evaluating configuration state rather than detecting active runtime threats.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO capabilities are provided by Microsoft Defender for Cloud? (Choose two.)

hard
  • ✓ A.Secure score and security recommendations
  • B.Endpoint detection and response (EDR)
  • ✓ C.Vulnerability assessment for VMs
  • D.Cloud Access Security Broker (CASB)
  • E.Security Information and Event Management (SIEM)

Why A: Microsoft Defender for Cloud provides a secure score and security recommendations (option A) as part of its Cloud Security Posture Management (CSPM) capabilities, continuously assessing resources against benchmarks like the Microsoft Cloud Security Benchmark and Azure Security Benchmark to surface prioritized remediation guidance. It also provides vulnerability assessment for VMs (option C) through integrated scanners such as Microsoft Defender for Servers' built-in vulnerability assessment powered by Qualys or the agentless scanning capability, surfacing CVEs and remediation steps in the portal. Option B (EDR) is a capability of Microsoft Defender for Endpoint, not Defender for Cloud itself, even though Defender for Servers can auto-provision the Defender for Endpoint agent. Option D (CASB) is delivered by Microsoft Defender for Cloud Apps, a separate product in the Defender suite. Option E (SIEM) is provided by Microsoft Sentinel, not Defender for Cloud.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.