SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your company uses Microsoft Defender XDR. You need to integrate threat intelligence from external sources to enrich alerts and automate response actions. Which feature should you use?
⚠ Common exam trap
Many candidates confuse 'threat intelligence integration' with 'threat analytics' (option B), assuming both provide external threat data, but threat analytics only surfaces Microsoft's pre-analyzed reports, not custom external feeds.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat intelligence integration
Microsoft Defender XDR's threat intelligence integration (option D) allows you to import custom threat indicators (IOCs) from external sources—such as STIX/TAXII feeds, APIs, or manual uploads—into the Microsoft 365 Defender platform. These indicators are then used to enrich alerts, trigger automated response actions via custom detection rules, and correlate with telemetry across endpoints, email, and identities. This directly meets the requirement to integrate external threat intelligence for enrichment and automation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Automation rules
Why it's wrong here
Automation rules in Microsoft Defender XDR are designed to automatically apply actions, such as suppressing alerts or setting investigation states, based on predefined conditions of *existing* alerts or incidents. These rules operate on data already present within the Defender XDR platform and are primarily used for workflow automation and alert management. They do not provide a mechanism for directly ingesting or integrating new external threat intelligence feeds or custom indicators of compromise (IOCs) into the system's core intelligence repository.
- ✗
Threat analytics
Why it's wrong here
Threat analytics within Microsoft Defender XDR provides comprehensive reports and insights curated by Microsoft's security researchers, detailing active threats, vulnerabilities, and attack campaigns. While this feature offers valuable threat intelligence, it is exclusively derived from Microsoft's own extensive security research and telemetry. It serves as an informational resource for understanding threats detected by Defender XDR, rather than a capability for users to import or integrate their own custom or third-party external threat intelligence feeds into the platform.
- ✗
Advanced hunting
Why it's wrong here
Advanced hunting is a powerful, query-based threat hunting tool within Microsoft Defender XDR that allows security analysts to proactively search for threats across their environment using Kusto Query Language (KQL). This tool operates on *existing* telemetry data collected by Defender XDR from endpoints, identities, and cloud applications. While analysts can leverage advanced hunting to query for indicators that might originate from external intelligence, it is fundamentally an investigation and detection mechanism, not a feature designed for the direct ingestion or integration of external threat intelligence feeds into the platform's core intelligence database.
- ✓
Threat intelligence integration
Why this is correct
Threat intelligence integration in Microsoft Defender XDR allows organizations to import custom indicators of compromise (IOCs) and threat intelligence feeds from various external sources. This capability enables security teams to enrich their existing alerts, detections, and investigations with context from third-party or proprietary threat intelligence platforms. By integrating external TI, Defender XDR can automatically correlate incoming security events against these custom indicators, significantly enhancing detection capabilities and providing more comprehensive insights into potential threats.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Threat intelligence
Threat intelligence is evidence-based knowledge about existing or emerging cyber threats that helps organizations defend against attacks.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.