SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
You are a security operations analyst for a company that uses Microsoft Defender XDR. The company wants to automatically block and remediate malicious files and processes detected on onboarded Windows devices without requiring analyst intervention. Which Microsoft Defender XDR component should you configure?
⚠ Common exam trap
Many candidates confuse attack disruption, which contains active attacks at the XDR level, with automated investigation and response, which applies endpoint remediation based on per-alert automation levels.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated investigation and response in Microsoft Defender for Endpoint
Automated investigation and response in Defender for Endpoint is the feature that investigates alerts and applies remediation actions based on configured automation levels. Setting the automation level to full enables automatic remediation of malicious files and processes on onboarded devices. Other Defender XDR components provide hunting, attack disruption, or identity monitoring but do not handle per-alert endpoint remediation configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automated investigation and response in Microsoft Defender for Endpoint
Why this is correct
Automated investigation and response in Defender for Endpoint uses automation levels to investigate alerts and apply remediation actions such as quarantining files, stopping processes, and isolating devices. Configuring the automation level to full allows remediation without analyst approval, directly meeting the requirement to automatically block and remediate malicious files and processes on onboarded Windows devices.
- ✗
Advanced hunting in Microsoft Defender XDR
Why it's wrong here
Advanced hunting is a query-based tool that lets analysts proactively search telemetry across Defender XDR workloads. It does not automatically block or remediate threats. Using advanced hunting can help identify malicious activity, but it requires manual action to respond. It is not the automation component that enforces remediation on endpoints without analyst intervention.
- ✗
Microsoft Defender for Identity sensor
Why it's wrong here
The Defender for Identity sensor monitors on-premises Active Directory domain controller traffic to detect identity-based attacks. It does not manage endpoint files or processes and cannot automatically remediate malicious files on Windows devices. Configuring it would not address the need to block and remediate endpoint threats automatically, because its scope is identity threat detection, not endpoint response.
- ✗
Attack disruption in Microsoft Defender XDR
Why it's wrong here
Attack disruption automatically contains advanced attacks in progress across Microsoft Defender XDR workloads, such as containing a compromised user or device during a high-confidence attack. It is not the component used to configure per-alert automated investigation and remediation of files and processes. While it can block attack progress, it does not replace the automation settings that handle routine malicious file remediation.
Go deeper
Related to this question
Learn chapter
Microsoft Defender for Identity
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
Key term
Defender for Endpoint
Microsoft Defender for Endpoint is a cloud-delivered enterprise security solution designed to protect devices from cyber threats using behavioral analysis, machine learning, and automated investigation.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.