SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which THREE capabilities are provided by Microsoft Defender XDR (formerly Microsoft 365 Defender)? (Choose three.)
⚠ Common exam trap
Test-takers frequently confuse Microsoft Defender XDR's unified threat protection capabilities with broader Microsoft 365 security features like compliance (Purview) or device management (Intune), leading them to select data classification or MDM as valid options.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identity threat detection
Microsoft Defender XDR is a unified extended detection and response suite that correlates signals across identities, endpoints, email, and collaboration tools. Option A (Identity threat detection) is correct because Microsoft Defender for Identity is a core component of Defender XDR, detecting advanced identity-based attacks such as pass-the-hash, Kerberoasting, and reconnaissance against Active Directory. Option C (Endpoint detection and response (EDR)) is correct because Microsoft Defender for Endpoint provides EDR capabilities—behavioral monitoring, attack timeline, and automated investigation and response—within the Defender XDR portal. Option E (Email and collaboration protection) is correct because Microsoft Defender for Office 365 delivers protection against phishing, malware, and business email compromise across Exchange Online, Teams, SharePoint, and OneDrive. Option B (Data classification and labeling) is not part of Defender XDR; that capability belongs to Microsoft Purview Information Protection (sensitivity labels and data classification). Option D (Mobile device management (MDM)) is not provided by Defender XDR; MDM is delivered by Microsoft Intune, although Defender for Endpoint can integrate with Intune for onboarding and compliance signals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identity threat detection
Why this is correct
Microsoft Defender for Identity provides robust identity threat detection by continuously monitoring on-premises Active Directory signals and cloud identities for suspicious activities and anomalous behaviors. It leverages behavioral analytics and machine learning to identify advanced attacks such as pass-the-hash, golden ticket, and brute-force attempts, offering real-time insights into potential compromises across hybrid environments. This capability is a core component of Microsoft Defender XDR, integrating with other Defender services to provide a comprehensive view of identity-related risks and incidents.
- ✗
Data classification and labeling
Why it's wrong here
Data classification and labeling are core capabilities provided by Microsoft Purview Information Protection, not directly by Microsoft Defender. Microsoft Purview enables organizations to discover, classify, and protect sensitive data across their digital estate using sensitivity labels and data loss prevention (DLP) policies. While Defender services protect against threats that might target data, they do not inherently perform the classification and labeling functions themselves, which are distinct information governance and compliance features.
- ✓
Endpoint detection and response (EDR)
Why this is correct
Microsoft Defender for Endpoint delivers advanced Endpoint Detection and Response (EDR) capabilities by continuously monitoring device activity for malicious behavior and suspicious events. It provides real-time visibility into endpoint security posture, automatically investigates incidents, and offers automated remediation actions to contain threats. This service protects a wide range of endpoints, including workstations, servers, and mobile devices, by leveraging behavioral analytics and cloud-powered threat intelligence to detect sophisticated attacks.
- ✗
Mobile device management (MDM)
Why it's wrong here
Mobile Device Management (MDM) is a primary function of Microsoft Intune, which is part of Microsoft Endpoint Manager, rather than a direct capability of Microsoft Defender. Intune focuses on enrolling, configuring, and managing mobile devices and applications, ensuring they comply with organizational security policies. While Defender for Endpoint can extend protection to mobile devices, Intune is responsible for the foundational device management, policy enforcement, and application deployment aspects, which are distinct from threat detection and response.
- ✓
Email and collaboration protection
Why this is correct
Microsoft Defender for Office 365 provides comprehensive email and collaboration protection by safeguarding against advanced threats like phishing, business email compromise (BEC), malware, and spam across email, Microsoft Teams, SharePoint Online, and OneDrive for Business. It utilizes advanced analytics, safe attachments, and safe links features to proactively detect and neutralize threats before they reach users. This critical security layer ensures the integrity and safety of an organization's most frequently used communication and collaboration platforms.
Go deeper
Related to this question
Learn chapter
Microsoft Purview
Key term
Pass-the-hash
Pass-the-hash is a cyberattack where an attacker captures the hash of a user's password and uses it to authenticate to other systems without ever knowing the actual password.
Key term
Microsoft Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email and collaboration security service that protects organizations against malicious threats like phishing, malware, and spam in email messages and Office 365 apps.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.