Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Which TWO of the following are capabilities of Microsoft Defender for Office 365?

⚠ Common exam trap

Candidates often confuse the broader Microsoft 365 Defender suite (which includes Defender for Office 365, Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps) with the specific capabilities of Defender for Office 365 alone, leading them to select features like UEBA or device compliance that belong to other security products.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scan email attachments in a sandbox environment before delivery

Option A is correct because Microsoft Defender for Office 365 includes Safe Attachments, which detonates email attachments in a sandbox (virtual environment) to detect malicious behavior before delivering the message. Option B is correct because Defender for Office 365 provides anti-phishing policies with impersonation protection that detect spoofed or impersonated senders (e.g., executives, domains) to defend against spear-phishing. Option C is incorrect because device compliance policies for mobile devices are enforced by Microsoft Intune (part of Microsoft Endpoint Manager), not Defender for Office 365. Option D is incorrect because legal hold for eDiscovery is a Microsoft Purview (Exchange/Compliance) capability, not a Defender for Office 365 feature. Option E is incorrect because monitoring user behavior for compromised accounts is handled by Microsoft Defender for Identity (or Entra ID Protection), not Defender for Office 365.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Scan email attachments in a sandbox environment before delivery

    Why this is correct

    Microsoft Defender for Office 365, a core component of Microsoft Defender XDR, includes Safe Attachments, which proactively scans email attachments. This capability detonates attachments in a virtual sandbox environment to analyze their behavior for malicious content before they are delivered to the user's inbox, effectively preventing zero-day malware and advanced threats from reaching endpoints.

  • ✓

    Protect against spear-phishing attacks using impersonation protection

    Why this is correct

    Microsoft Defender for Office 365, a key part of Microsoft Defender XDR, provides robust impersonation protection specifically designed to combat spear-phishing attacks. This feature identifies and blocks emails where attackers attempt to mimic trusted senders, such as executives or known domains, by analyzing various email attributes and content for subtle anomalies indicative of highly targeted and personalized phishing attempts.

  • ✗

    Enforce device compliance policies for mobile devices

    Why it's wrong here

    Enforcing device compliance policies for mobile devices, such as requiring specific operating system versions, encryption, or a strong PIN, is a primary capability of Microsoft Intune. Intune, part of Microsoft Endpoint Manager, focuses on unified endpoint management (UEM) and mobile device management (MDM), ensuring devices meet organizational security standards before accessing corporate resources, which is distinct from threat detection.

  • ✗

    Place a legal hold on mailboxes for eDiscovery

    Why it's wrong here

    Placing a legal hold on mailboxes and other content locations for eDiscovery purposes is a core function of Microsoft Purview eDiscovery, specifically through its Standard and Premium solutions. These tools are designed for legal and compliance teams to preserve, collect, and analyze electronic content for litigation, regulatory investigations, or internal inquiries, falling under information governance rather than real-time threat protection.

  • ✗

    Monitor user behavior for compromised accounts

    Why it's wrong here

    Monitoring user behavior for signs of compromised accounts, including detecting suspicious activities like impossible travel, unusual resource access patterns, or privilege escalation, is a primary capability of Microsoft Defender for Identity. This solution leverages Active Directory signals and behavioral analytics to identify and alert on identity-based threats, distinguishing it from endpoint, email, or cloud app protection.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.