SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which TWO Microsoft security solutions can be used to detect and respond to threats across email, endpoints, and identities? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse Microsoft Defender for Cloud Apps (a CASB focused on cloud app security) with a cross-domain detection and response solution, but it does not natively cover email or endpoint threat detection, making it an incorrect choice for this question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel
Microsoft Sentinel (option D) is correct because it is a cloud-native SIEM and SOAR platform that ingests logs from across the entire environment—including email, endpoints, and identity sources—to detect and respond to threats using analytics and automated playbooks. Microsoft Defender XDR (option E) is correct because it is a unified, pre- and post-breach detection and response solution that correlates signals across email (Exchange Online), endpoints (Microsoft Defender for Endpoint), and identities (Microsoft Defender for Identity).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Intune
Why it's wrong here
Intune is for device management, not threat detection.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Defender for Cloud Apps focuses on cloud apps, not endpoints.
- ✗
Microsoft Purview
Why it's wrong here
Purview is for governance and compliance, not threat detection.
- ✓
Microsoft Sentinel
Why this is correct
Sentinel provides SIEM and SOAR capabilities across multiple sources.
- ✓
Microsoft Defender XDR
Why this is correct
Defender XDR provides integrated detection and response across domains.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
SOAR
SOAR (Security Orchestration, Automation, and Response) is a technology stack that helps security teams automate responses to threats by integrating various security tools and standardizing workflows.
Key term
Defender for Identity
Defender for Identity is a cloud-based security solution that detects, investigates, and responds to advanced identity threats targeting on-premises Active Directory and cloud identities.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.