SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which THREE Microsoft Defender XDR components are included in the unified security operations platform? (Select three.)
⚠ Common exam trap
Many exam-takers confuse Microsoft Defender for Cloud (a CSPM/CWPP tool) with a component of the unified XDR platform, when in fact it is a separate security solution focused on cloud infrastructure, not part of the Microsoft 365 Defender XDR suite.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Office 365
Microsoft Defender XDR (Extended Detection and Response) unifies signals from across the Microsoft 365 Defender portal. Microsoft Defender for Office 365 is a core component because it protects email, SharePoint, OneDrive, and Teams from threats like phishing and malware, and its alerts feed directly into the unified XDR incident queue. This integration allows cross-domain correlation with endpoint, identity, and cloud app signals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Office 365
Why this is correct
Microsoft Defender for Office 365 is a core component of Microsoft Defender XDR, providing robust protection against sophisticated threats originating from email and collaboration tools. It safeguards against phishing, spam, malware, and business email compromise across Exchange Online, SharePoint, OneDrive, and Microsoft Teams, integrating critical threat signals into the unified XDR platform for comprehensive incident response and automated remediation.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is a distinct cloud security solution focused on cloud security posture management (CSPM) and cloud workload protection (CWP) across multi-cloud and hybrid environments. While it is part of the broader Microsoft Defender family, it operates at the infrastructure and platform level, securing Azure, AWS, and GCP resources, and is not considered a core component of the unified Microsoft Defender XDR suite, which primarily focuses on endpoints, identities, email, and cloud apps.
- ✓
Microsoft Defender for Identity
Why this is correct
Microsoft Defender for Identity is an essential component of Microsoft Defender XDR, specializing in securing hybrid identity environments. It monitors on-premises Active Directory and Azure Active Directory signals to detect, investigate, and respond to advanced threats like credential theft, lateral movement, and privilege escalation, providing crucial identity-based insights that are correlated with other signals within the unified XDR portal for holistic threat detection.
- ✓
Microsoft Defender for Endpoint
Why this is correct
Microsoft Defender for Endpoint is a foundational component of Microsoft Defender XDR, delivering comprehensive endpoint detection and response (EDR), next-generation protection, and vulnerability management capabilities. It secures devices across various operating systems, including Windows, macOS, Linux, Android, and iOS, by collecting rich telemetry and providing advanced threat intelligence that feeds directly into the unified XDR platform for automated investigation and remediation.
- ✗
Microsoft Defender for IoT
Why it's wrong here
Microsoft Defender for IoT is a specialized security solution designed to protect unmanaged Internet of Things (IoT), operational technology (OT), and industrial control systems (ICS) environments. It provides agentless network monitoring and threat detection for these unique industrial networks, which are distinct from the IT environments secured by the core Microsoft Defender XDR components. Therefore, it is not considered part of the unified XDR platform that focuses on user, endpoint, email, and application security.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Extended Detection and Response
Extended Detection and Response (XDR) is a security approach that collects and analyzes data from multiple sources like endpoints, networks, servers, and email to detect and stop threats more effectively.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.