SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
You are a security administrator for Contoso Ltd. The company uses Microsoft Defender XDR, Microsoft Sentinel, and Microsoft Entra ID. Recently, several users reported receiving phishing emails that bypassed the existing anti-phishing policies. The security team suspects that attackers are using sophisticated techniques to evade detection. You need to enhance the email security posture by implementing a solution that uses AI and machine learning to detect advanced phishing attempts, including those using social engineering and impersonation. Which Microsoft solution should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Office 365
Microsoft Defender for Office 365 includes advanced anti-phishing capabilities with AI and machine learning, such as impersonation protection and spoof intelligence. Microsoft Sentinel is a SIEM/SOAR, not an email security solution. Defender for Cloud Apps is a CASB. Defender for Identity identifies threats via on-premises AD signals. Microsoft Purview focuses on compliance and data governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. While it ingests security data from various sources, including email systems, to detect and investigate threats, it does not provide direct, real-time preventative protection against phishing attacks at the email gateway or mailbox level. Its primary role is post-delivery threat hunting and incident response, rather than pre-delivery email filtering.
- ✓
Microsoft Defender for Office 365
Why this is correct
Microsoft Defender for Office 365 is specifically designed to protect email, collaboration, and productivity services from advanced threats like phishing, business email compromise (BEC), and malware. It employs machine learning models and detonation chambers to analyze email content, attachments, and links in real-time, identifying and blocking sophisticated phishing attempts, impersonation attacks, and zero-day exploits before they reach user inboxes. This comprehensive suite includes anti-phishing policies, Safe Attachments, and Safe Links to proactively safeguard users.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing visibility into cloud applications and services used within an organization, including "shadow IT." Its primary capabilities involve discovering cloud apps, enforcing data loss prevention (DLP) policies, monitoring user activity, and controlling access to sanctioned and unsanctioned cloud applications. It does not, however, directly scan or protect incoming email traffic from phishing attempts.
- ✗
Microsoft Defender for Identity
Why it's wrong here
Microsoft Defender for Identity is a cloud-based security solution that leverages on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions. It focuses on protecting user identities and credentials by monitoring domain controllers and AD FS for suspicious behavior, lateral movement paths, and privilege escalation. This service is not involved in the direct protection or scanning of email content for phishing threats.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
Key term
Impersonation
Impersonation is a security attack where an attacker pretends to be a legitimate person or system to gain unauthorized access, steal data, or commit fraud.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are the security administrator for a company using Microsoft Defender XDR. A user reports receiving a suspicious email with a link. What Microsoft Defender XDR feature should you use to investigate the email's threat level?
easy- ✓ A.Email & collaboration in Microsoft Defender XDR
- B.Microsoft Defender for Endpoint
- C.Microsoft Defender for Cloud Apps
- D.Microsoft Defender for Identity
Why A: Microsoft Defender XDR's Email & collaboration feature (part of Defender for Office 365) is the correct tool for investigating a suspicious email. It provides a unified investigation experience, including threat explorer, email entity pages, and detonation analysis, allowing you to inspect the email's headers, attachments, URLs, and determine its threat level using Microsoft's threat intelligence and machine learning models.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.