SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization wants to automatically investigate and remediate email-based threats in Microsoft 365. Which security solution should you use?
⚠ Common exam trap
Many exam-takers confuse Microsoft Defender for Office 365 with Microsoft Defender for Endpoint, assuming endpoint protection covers email threats, but email security is a separate workload requiring dedicated protection for Exchange Online and SharePoint Online.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Office 365
Microsoft Defender for Office 365 is the correct solution because it is specifically designed to protect against email-based threats such as phishing, malware, and business email compromise (BEC). It provides automated investigation and remediation capabilities through features like Automated Investigation and Response (AIR) and Threat Explorer, which can automatically analyze and remediate malicious emails, attachments, and URLs in Exchange Online.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Microsoft Defender for Endpoint is a unified endpoint security platform designed to protect devices like workstations, servers, and mobile devices from advanced threats. It provides capabilities such as endpoint detection and response (EDR), vulnerability management, and next-generation antivirus to secure the device itself. While crucial for device security, its scope does not include the automated investigation and remediation of threats specifically originating from email or collaboration tools within the Office 365 environment.
- ✓
Microsoft Defender for Office 365
Why this is correct
Microsoft Defender for Office 365 is specifically engineered to protect an organization from sophisticated threats in email, links, and collaboration tools like Microsoft Teams. It leverages advanced anti-phishing, anti-malware, and Safe Attachments/Safe Links technologies to detect and block threats. Crucially, it includes Automated Investigation and Response (AIR) capabilities that automatically investigate alerts, determine the scope of a threat, and take recommended or approved remediation actions for email-borne attacks, directly addressing the requirement.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing comprehensive visibility, control over data travel, and sophisticated threat protection across all cloud applications, not solely Office 365. It helps identify and combat shadow IT, enforce data loss prevention policies, and detect anomalous user behavior across various SaaS applications. While it monitors activities within Office 365, its primary role is not the direct, automated investigation and remediation of email-specific threats originating from the mail flow itself.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a scalable, cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It aggregates security data from across an organization's entire digital estate, including various Microsoft 365 Defender products, for centralized analysis, threat hunting, and custom automation. While Sentinel can orchestrate responses and automate workflows based on ingested alerts, it does not provide the native, first-line automated investigation and remediation specifically for email threats at the service level like Defender for Office 365 does.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email security service that protects organizations against advanced threats like phishing, malware, and business email compromise by scanning emails, attachments, and links in real time.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.