Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Which THREE Microsoft Defender XDR components are included in the unified security operations platform? (Select three.)

⚠ Common exam trap

Many exam-takers confuse Microsoft Defender for Cloud (a CSPM/CWPP tool) with a component of the unified XDR platform, when in fact it is a separate security solution focused on cloud infrastructure, not part of the Microsoft 365 Defender XDR suite.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Office 365

Microsoft Defender XDR (Extended Detection and Response) unifies signals from across the Microsoft 365 Defender portal. Microsoft Defender for Office 365 is a core component because it protects email, SharePoint, OneDrive, and Teams from threats like phishing and malware, and its alerts feed directly into the unified XDR incident queue. This integration allows cross-domain correlation with endpoint, identity, and cloud app signals.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Office 365

    Why this is correct

    Microsoft Defender for Office 365 is a core component of Microsoft Defender XDR, providing robust protection against sophisticated threats originating from email and collaboration tools. It safeguards against phishing, spam, malware, and business email compromise across Exchange Online, SharePoint, OneDrive, and Microsoft Teams, integrating critical threat signals into the unified XDR platform for comprehensive incident response and automated remediation.

  • Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud is a distinct cloud security solution focused on cloud security posture management (CSPM) and cloud workload protection (CWP) across multi-cloud and hybrid environments. While it is part of the broader Microsoft Defender family, it operates at the infrastructure and platform level, securing Azure, AWS, and GCP resources, and is not considered a core component of the unified Microsoft Defender XDR suite, which primarily focuses on endpoints, identities, email, and cloud apps.

  • Microsoft Defender for Identity

    Why this is correct

    Microsoft Defender for Identity is an essential component of Microsoft Defender XDR, specializing in securing hybrid identity environments. It monitors on-premises Active Directory and Azure Active Directory signals to detect, investigate, and respond to advanced threats like credential theft, lateral movement, and privilege escalation, providing crucial identity-based insights that are correlated with other signals within the unified XDR portal for holistic threat detection.

  • Microsoft Defender for Endpoint

    Why this is correct

    Microsoft Defender for Endpoint is a foundational component of Microsoft Defender XDR, delivering comprehensive endpoint detection and response (EDR), next-generation protection, and vulnerability management capabilities. It secures devices across various operating systems, including Windows, macOS, Linux, Android, and iOS, by collecting rich telemetry and providing advanced threat intelligence that feeds directly into the unified XDR platform for automated investigation and remediation.

  • Microsoft Defender for IoT

    Why it's wrong here

    Microsoft Defender for IoT is a specialized security solution designed to protect unmanaged Internet of Things (IoT), operational technology (OT), and industrial control systems (ICS) environments. It provides agentless network monitoring and threat detection for these unique industrial networks, which are distinct from the IT environments secured by the core Microsoft Defender XDR components. Therefore, it is not considered part of the unified XDR platform that focuses on user, endpoint, email, and application security.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.