Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

You are a security operations analyst for a company that uses Microsoft Defender XDR. The company wants to automatically block and remediate malicious files and processes detected on onboarded Windows devices without requiring analyst intervention. Which Microsoft Defender XDR component should you configure?

⚠ Common exam trap

Many candidates confuse attack disruption, which contains active attacks at the XDR level, with automated investigation and response, which applies endpoint remediation based on per-alert automation levels.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated investigation and response in Microsoft Defender for Endpoint

Automated investigation and response in Defender for Endpoint is the feature that investigates alerts and applies remediation actions based on configured automation levels. Setting the automation level to full enables automatic remediation of malicious files and processes on onboarded devices. Other Defender XDR components provide hunting, attack disruption, or identity monitoring but do not handle per-alert endpoint remediation configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Automated investigation and response in Microsoft Defender for Endpoint

    Why this is correct

    Automated investigation and response in Defender for Endpoint uses automation levels to investigate alerts and apply remediation actions such as quarantining files, stopping processes, and isolating devices. Configuring the automation level to full allows remediation without analyst approval, directly meeting the requirement to automatically block and remediate malicious files and processes on onboarded Windows devices.

  • ✗

    Advanced hunting in Microsoft Defender XDR

    Why it's wrong here

    Advanced hunting is a query-based tool that lets analysts proactively search telemetry across Defender XDR workloads. It does not automatically block or remediate threats. Using advanced hunting can help identify malicious activity, but it requires manual action to respond. It is not the automation component that enforces remediation on endpoints without analyst intervention.

  • ✗

    Microsoft Defender for Identity sensor

    Why it's wrong here

    The Defender for Identity sensor monitors on-premises Active Directory domain controller traffic to detect identity-based attacks. It does not manage endpoint files or processes and cannot automatically remediate malicious files on Windows devices. Configuring it would not address the need to block and remediate endpoint threats automatically, because its scope is identity threat detection, not endpoint response.

  • ✗

    Attack disruption in Microsoft Defender XDR

    Why it's wrong here

    Attack disruption automatically contains advanced attacks in progress across Microsoft Defender XDR workloads, such as containing a compromised user or device during a high-confidence attack. It is not the component used to configure per-alert automated investigation and remediation of files and processes. While it can block attack progress, it does not replace the automation settings that handle routine malicious file remediation.

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.