Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Which THREE capabilities are provided by Microsoft Defender XDR (formerly Microsoft 365 Defender)? (Choose three.)

⚠ Common exam trap

Test-takers frequently confuse Microsoft Defender XDR's unified threat protection capabilities with broader Microsoft 365 security features like compliance (Purview) or device management (Intune), leading them to select data classification or MDM as valid options.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identity threat detection

Microsoft Defender XDR is a unified extended detection and response suite that correlates signals across identities, endpoints, email, and collaboration tools. Option A (Identity threat detection) is correct because Microsoft Defender for Identity is a core component of Defender XDR, detecting advanced identity-based attacks such as pass-the-hash, Kerberoasting, and reconnaissance against Active Directory. Option C (Endpoint detection and response (EDR)) is correct because Microsoft Defender for Endpoint provides EDR capabilities—behavioral monitoring, attack timeline, and automated investigation and response—within the Defender XDR portal. Option E (Email and collaboration protection) is correct because Microsoft Defender for Office 365 delivers protection against phishing, malware, and business email compromise across Exchange Online, Teams, SharePoint, and OneDrive. Option B (Data classification and labeling) is not part of Defender XDR; that capability belongs to Microsoft Purview Information Protection (sensitivity labels and data classification). Option D (Mobile device management (MDM)) is not provided by Defender XDR; MDM is delivered by Microsoft Intune, although Defender for Endpoint can integrate with Intune for onboarding and compliance signals.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identity threat detection

    Why this is correct

    Microsoft Defender for Identity provides robust identity threat detection by continuously monitoring on-premises Active Directory signals and cloud identities for suspicious activities and anomalous behaviors. It leverages behavioral analytics and machine learning to identify advanced attacks such as pass-the-hash, golden ticket, and brute-force attempts, offering real-time insights into potential compromises across hybrid environments. This capability is a core component of Microsoft Defender XDR, integrating with other Defender services to provide a comprehensive view of identity-related risks and incidents.

  • ✗

    Data classification and labeling

    Why it's wrong here

    Data classification and labeling are core capabilities provided by Microsoft Purview Information Protection, not directly by Microsoft Defender. Microsoft Purview enables organizations to discover, classify, and protect sensitive data across their digital estate using sensitivity labels and data loss prevention (DLP) policies. While Defender services protect against threats that might target data, they do not inherently perform the classification and labeling functions themselves, which are distinct information governance and compliance features.

  • ✓

    Endpoint detection and response (EDR)

    Why this is correct

    Microsoft Defender for Endpoint delivers advanced Endpoint Detection and Response (EDR) capabilities by continuously monitoring device activity for malicious behavior and suspicious events. It provides real-time visibility into endpoint security posture, automatically investigates incidents, and offers automated remediation actions to contain threats. This service protects a wide range of endpoints, including workstations, servers, and mobile devices, by leveraging behavioral analytics and cloud-powered threat intelligence to detect sophisticated attacks.

  • ✗

    Mobile device management (MDM)

    Why it's wrong here

    Mobile Device Management (MDM) is a primary function of Microsoft Intune, which is part of Microsoft Endpoint Manager, rather than a direct capability of Microsoft Defender. Intune focuses on enrolling, configuring, and managing mobile devices and applications, ensuring they comply with organizational security policies. While Defender for Endpoint can extend protection to mobile devices, Intune is responsible for the foundational device management, policy enforcement, and application deployment aspects, which are distinct from threat detection and response.

  • ✓

    Email and collaboration protection

    Why this is correct

    Microsoft Defender for Office 365 provides comprehensive email and collaboration protection by safeguarding against advanced threats like phishing, business email compromise (BEC), malware, and spam across email, Microsoft Teams, SharePoint Online, and OneDrive for Business. It utilizes advanced analytics, safe attachments, and safe links features to proactively detect and neutralize threats before they reach users. This critical security layer ensures the integrity and safety of an organization's most frequently used communication and collaboration platforms.

Go deeper

Related to this question

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.