Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

Which THREE are capabilities of Microsoft Defender XDR?

⚠ Common exam trap

SC-900 often tests whether candidates can separate Defender XDR (threat detection and response) from Intune (device compliance) and Purview (data classification) — candidates pick device compliance because Defender XDR surfaces device risk, but it does not manage compliance policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated investigation and remediation

Option B is correct because Microsoft Defender XDR provides automated investigation and remediation (AIR) that uses playbooks to automatically investigate alerts and take remediation actions across affected assets. Option C is correct because Defender XDR correlates alerts into unified incidents spanning email (Defender for Office 365), endpoints (Defender for Endpoint), and identities (Defender for Identity), giving a single incident queue and management experience. Option D is correct because Defender XDR enables cross-domain threat hunting, allowing advanced hunting queries over unified data from endpoints, email, identities, and cloud apps in one schema. Option A is not correct because device compliance policy management is a Microsoft Intune/Endpoint Manager capability, not a Defender XDR function. Option E is not correct because data classification and labeling is handled by Microsoft Purview Information Protection, not Defender XDR.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Device compliance policy management

    Why it's wrong here

    Device compliance policy management belongs to Intune, which enforces configuration and compliance on endpoints; Defender XDR correlates signals and automates response. It is tempting because both feed the same portal, but compliance enforcement is a separate workload from detection and remediation.

  • ✓

    Automated investigation and remediation

    Why this is correct

    Automated investigation and remediation is a core Microsoft Defender XDR capability, using correlated signals across endpoints, identities, email and cloud apps to trigger self-healing response actions. It satisfies the stem's requirement for a genuine Defender XDR capability rather than a standalone product feature.

  • ✓

    Incident management across email, endpoints, and identities

    Why this is correct

    Incident management spanning email, endpoints, and identities is a core Microsoft Defender XDR capability, correlating alerts from Defender for Office 365, Defender for Endpoint, and Microsoft Entra ID Protection into unified incidents. This cross-domain correlation satisfies the stem's requirement for integrated threat detection and response across multiple workloads.

  • ✓

    Cross-domain threat hunting

    Why this is correct

    Cross-domain threat hunting unifies signals from endpoints, identities, email and cloud apps into a single Microsoft Defender portal, letting analysts correlate incidents spanning multiple workloads. This satisfies the stem's requirement for a Defender XDR capability, since native integration across those domains is what distinguishes the suite from standalone products.

  • ✗

    Data classification and labeling

    Why it's wrong here

    Data classification and labelling belongs to Microsoft Purview, which discovers and tags sensitive content; Defender XDR correlates signals across endpoints, identities, email and cloud apps to detect and respond to attacks. It is tempting because both sit in the Defender portal, but classification is a governance capability, not an XDR detection or response one.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.