Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Which TWO Microsoft security solutions can be used to detect and respond to threats across email, endpoints, and identities? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse Microsoft Defender for Cloud Apps (a CASB focused on cloud app security) with a cross-domain detection and response solution, but it does not natively cover email or endpoint threat detection, making it an incorrect choice for this question.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Sentinel

Microsoft Defender XDR (E) is correct because it is the extended detection and response platform that natively correlates signals across email (Defender for Office 365), endpoints (Defender for Endpoint), identities (Defender for Identity), and cloud apps, providing unified detection and automated response. Microsoft Sentinel (D) is correct because it is a cloud-native SIEM/SOAR solution that ingests telemetry from email, endpoint, identity, and other sources via connectors, then uses analytics rules, fusion, and playbooks to detect and respond to threats across those domains. Microsoft Intune (A) is not correct because it is a mobile device and endpoint management (MDM/MAM) service for configuration and compliance, not a threat detection and response solution. Microsoft Defender for Cloud Apps (B) is not correct here because, although it is part of the Defender XDR suite, on its own it is a CASB focused on cloud app discovery, session control, and SaaS threat protection rather than covering email, endpoints, and identities. Microsoft Purview (C) is not correct because it is a data governance, compliance, and information protection suite (DLP, eDiscovery, sensitivity labels), not a cross-domain threat detection and response platform.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Intune is for device management, not threat detection.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Defender for Cloud Apps focuses on cloud apps, not endpoints.

  • ✗

    Microsoft Purview

    Why it's wrong here

    Purview is for governance and compliance, not threat detection.

  • ✓

    Microsoft Sentinel

    Why this is correct

    Microsoft Sentinel is a cloud-native SIEM and SOAR platform that ingests signals from Microsoft 365, Defender services and Microsoft Entra ID, correlating them into incidents and automating response with playbooks. This cross-domain visibility satisfies the requirement to detect and respond across email, endpoints and identities.

  • ✓

    Microsoft Defender XDR

    Why this is correct

    Microsoft Defender XDR correlates signals from Defender for Office 365, Defender for Endpoint and Defender for Identity into unified incidents, enabling coordinated automated response across email, endpoints and identities. This native cross-domain correlation is exactly the detect-and-respond scope the scenario requires.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.