SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which TWO Microsoft security solutions can be used to detect and respond to threats across email, endpoints, and identities? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse Microsoft Defender for Cloud Apps (a CASB focused on cloud app security) with a cross-domain detection and response solution, but it does not natively cover email or endpoint threat detection, making it an incorrect choice for this question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel
Microsoft Defender XDR (E) is correct because it is the extended detection and response platform that natively correlates signals across email (Defender for Office 365), endpoints (Defender for Endpoint), identities (Defender for Identity), and cloud apps, providing unified detection and automated response. Microsoft Sentinel (D) is correct because it is a cloud-native SIEM/SOAR solution that ingests telemetry from email, endpoint, identity, and other sources via connectors, then uses analytics rules, fusion, and playbooks to detect and respond to threats across those domains. Microsoft Intune (A) is not correct because it is a mobile device and endpoint management (MDM/MAM) service for configuration and compliance, not a threat detection and response solution. Microsoft Defender for Cloud Apps (B) is not correct here because, although it is part of the Defender XDR suite, on its own it is a CASB focused on cloud app discovery, session control, and SaaS threat protection rather than covering email, endpoints, and identities. Microsoft Purview (C) is not correct because it is a data governance, compliance, and information protection suite (DLP, eDiscovery, sensitivity labels), not a cross-domain threat detection and response platform.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Intune
Why it's wrong here
Intune is for device management, not threat detection.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Defender for Cloud Apps focuses on cloud apps, not endpoints.
- ✗
Microsoft Purview
Why it's wrong here
Purview is for governance and compliance, not threat detection.
- ✓
Microsoft Sentinel
Why this is correct
Microsoft Sentinel is a cloud-native SIEM and SOAR platform that ingests signals from Microsoft 365, Defender services and Microsoft Entra ID, correlating them into incidents and automating response with playbooks. This cross-domain visibility satisfies the requirement to detect and respond across email, endpoints and identities.
- ✓
Microsoft Defender XDR
Why this is correct
Microsoft Defender XDR correlates signals from Defender for Office 365, Defender for Endpoint and Defender for Identity into unified incidents, enabling coordinated automated response across email, endpoints and identities. This native cross-domain correlation is exactly the detect-and-respond scope the scenario requires.
Go deeper
Related to this question
Learn chapter
Exact Data Match for Sensitive Info Types
Key term
SIEM
SIEM (Security Information and Event Management) is a system that collects and analyzes log data from across an IT environment to detect and respond to security threats in real time.
Key term
Defender for Identity
Defender for Identity is a cloud-based security solution that detects, investigates, and responds to advanced identity threats targeting on-premises Active Directory and cloud identities.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.