SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Which THREE are capabilities of Microsoft Defender XDR?
⚠ Common exam trap
SC-900 often tests whether candidates can separate Defender XDR (threat detection and response) from Intune (device compliance) and Purview (data classification) — candidates pick device compliance because Defender XDR surfaces device risk, but it does not manage compliance policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated investigation and remediation
Option B is correct because Microsoft Defender XDR provides automated investigation and remediation (AIR) that uses playbooks to automatically investigate alerts and take remediation actions across affected assets. Option C is correct because Defender XDR correlates alerts into unified incidents spanning email (Defender for Office 365), endpoints (Defender for Endpoint), and identities (Defender for Identity), giving a single incident queue and management experience. Option D is correct because Defender XDR enables cross-domain threat hunting, allowing advanced hunting queries over unified data from endpoints, email, identities, and cloud apps in one schema. Option A is not correct because device compliance policy management is a Microsoft Intune/Endpoint Manager capability, not a Defender XDR function. Option E is not correct because data classification and labeling is handled by Microsoft Purview Information Protection, not Defender XDR.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Device compliance policy management
Why it's wrong here
Device compliance policy management belongs to Intune, which enforces configuration and compliance on endpoints; Defender XDR correlates signals and automates response. It is tempting because both feed the same portal, but compliance enforcement is a separate workload from detection and remediation.
- ✓
Automated investigation and remediation
Why this is correct
Automated investigation and remediation is a core Microsoft Defender XDR capability, using correlated signals across endpoints, identities, email and cloud apps to trigger self-healing response actions. It satisfies the stem's requirement for a genuine Defender XDR capability rather than a standalone product feature.
- ✓
Incident management across email, endpoints, and identities
Why this is correct
Incident management spanning email, endpoints, and identities is a core Microsoft Defender XDR capability, correlating alerts from Defender for Office 365, Defender for Endpoint, and Microsoft Entra ID Protection into unified incidents. This cross-domain correlation satisfies the stem's requirement for integrated threat detection and response across multiple workloads.
- ✓
Cross-domain threat hunting
Why this is correct
Cross-domain threat hunting unifies signals from endpoints, identities, email and cloud apps into a single Microsoft Defender portal, letting analysts correlate incidents spanning multiple workloads. This satisfies the stem's requirement for a Defender XDR capability, since native integration across those domains is what distinguishes the suite from standalone products.
- ✗
Data classification and labeling
Why it's wrong here
Data classification and labelling belongs to Microsoft Purview, which discovers and tags sensitive content; Defender XDR correlates signals across endpoints, identities, email and cloud apps to detect and respond to attacks. It is tempting because both sit in the Defender portal, but classification is a governance capability, not an XDR detection or response one.
Go deeper
Related to this question
Learn chapter
Microsoft Purview
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.