nerdexam
Microsoft

MS-900 · Question #278

A company plans to implement Microsoft Defender XDR services in its Microsoft 365 environment. The company requires that its security solution: - Assesses the configuration of its internal network…

The correct answer is D. Defender Vulnerability Management. Explanation Microsoft Defender Vulnerability Management (option D) is purpose-built to discover and assess security weaknesses across an organization's environment, including network share configurations, browser extension permissions, expiring certificates, and installed…

Submitted by marco_it· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

A company plans to implement Microsoft Defender XDR services in its Microsoft 365 environment. The company requires that its security solution: - Assesses the configuration of its internal network shares. - Assesses browser extension permissions on devices. - Identifies expiring certificates that are installed on devices. - Identifies software that is installed on devices. You need to recommend a security solution. Which Microsoft Defender XDR service should you use?

Options

  • ADefender for Endpoint
  • BDefender for Cloud Apps
  • CDefender for Office 365
  • DDefender Vulnerability Management
  • EDefender for Identity

How the community answered

(19 responses)
  • A
    11% (2)
  • C
    5% (1)
  • D
    79% (15)
  • E
    5% (1)

Explanation

Explanation

Microsoft Defender Vulnerability Management (option D) is purpose-built to discover and assess security weaknesses across an organization's environment, including network share configurations, browser extension permissions, expiring certificates, and installed software inventory - all of which directly match the requirements listed in the question.

Why the distractors are wrong:

  • A (Defender for Endpoint): Focuses on endpoint detection, response, and threat protection rather than the broad vulnerability and configuration assessment functions described.
  • B (Defender for Cloud Apps): Specializes in cloud application security, shadow IT discovery, and SaaS app governance - not device-level configuration assessments.
  • C (Defender for Office 365): Targets email and collaboration tool threats (phishing, malware in attachments) and has no relevance to device certificates or network shares.
  • E (Defender for Identity): Monitors Active Directory signals to detect identity-based attacks and compromised accounts - not software inventory or device configuration.

Memory Tip: Think of Vulnerability Management = "What's wrong with my devices and configs?" - if the question asks about assessing, inventorying, or identifying weaknesses on devices (certificates, extensions, software, shares), Defender Vulnerability Management is your answer. The key word pattern is "assesses" + "identifies" at the device/config level.

Topics

#Microsoft Defender XDR#Vulnerability Management#Security assessment#Device security

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice