Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

You are a security administrator for a company that uses Microsoft 365 E5. The security team wants to automatically investigate and remediate phishing and malware threats in email without manual intervention, and they need a solution that correlates signals across email, endpoints, and identities. Which Microsoft Defender XDR capability should they configure?

⚠ Common exam trap

The trap here is choosing a preventive email control like Safe Attachments or a training feature, rather than the automated investigation and response engine that actually remediates threats and correlates signals across domains.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated investigation and response in Microsoft Defender for Office 365

Automated investigation and response in Defender for Office 365 is designed to automatically investigate and remediate email threats, and within Microsoft Defender XDR it correlates those investigations with endpoint and identity signals. Attack simulation training, Safe Attachments, and eDiscovery provide education, prevention, or legal hold but not automated cross-domain threat investigation and remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Safe Attachments policy in Microsoft Defender for Office 365

    Why it's wrong here

    Safe Attachments detonates email attachments in a sandbox to detect malicious content and can block delivery. It is a preventive control, not an automated investigation and response engine. It does not automatically investigate incidents or correlate signals across email, endpoints, and identities, so it does not fully satisfy the requirement for automatic investigation and remediation.

  • ✗

    Attack simulation training in Microsoft Defender for Office 365

    Why it's wrong here

    Attack simulation training lets administrators run simulated phishing campaigns to educate users and measure susceptibility. It does not automatically investigate or remediate real phishing and malware threats in email. While it improves awareness, it does not provide the automated response or cross-domain correlation required by the security team's scenario.

  • ✓

    Automated investigation and response in Microsoft Defender for Office 365

    Why this is correct

    Automated investigation and response in Defender for Office 365 automatically investigates email threats such as phishing and malware, and applies remediation like soft delete or move to junk. In Microsoft Defender XDR, these investigations correlate with endpoint and identity signals to provide a unified view. Configuring it meets the need for automatic email threat remediation with cross-domain correlation.

  • ✗

    Microsoft Purview eDiscovery in Microsoft 365

    Why it's wrong here

    eDiscovery is used for legal and compliance purposes to identify, hold, and export content for investigations. It does not automatically investigate or remediate phishing and malware threats in email. It also does not correlate security signals across workloads. Using eDiscovery would not provide the automated threat response or XDR correlation the team needs.

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.