nerdexam
Microsoft

MS-900 · Question #279

Hotspot Question A company uses Microsoft 365. Select the answer that correctly completes the sentence. Answer:

The correct answer is To provide a tool for security analyst triage, incident response, threat hunting, vulnerability management workflows, and recent security articles from Microsoft, the company should use: Defender Threat Intelligence. The correct answer is Defender Threat Intelligence because its capabilities directly align with providing a comprehensive tool for security analyst triage, incident response, threat hunting, vulnerability management workflows, and access to Microsoft's security articles.

Submitted by mateo_ar· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

Hotspot Question A company uses Microsoft 365. Select the answer that correctly completes the sentence. Answer:

Exhibit

MS-900 question #279 exhibit

Answer Area

  • To provide a tool for security analyst triage, incident response, threat hunting, vulnerability management workflows, and recent security articles from Microsoft, the company should useDefender Threat Intelligence
    Defender for Cloud AppsDefender for Office 365Defender Threat IntelligenceDefender Vulnerability Management

Explanation

The correct answer is Defender Threat Intelligence because its capabilities directly align with providing a comprehensive tool for security analyst triage, incident response, threat hunting, vulnerability management workflows, and access to Microsoft's security articles.

Approach. The test-taker must click on the dropdown menu and select 'Defender Threat Intelligence'. This is the correct choice because Microsoft Defender Threat Intelligence (MDTI) is specifically designed to provide proactive threat intelligence, deep insights into adversary infrastructure and methods, and tools for threat hunting, incident response, and vulnerability management workflows. It aggregates global threat data from Microsoft's vast ecosystem and makes it accessible for security analysts, including recent security articles and research, to enhance an organization's security posture and response capabilities. The description in the question directly matches the core functions of MDTI.

Common mistakes.

  • common_mistake. Selecting any option other than 'Defender Threat Intelligence' would be incorrect because their primary focus areas do not encompass the full range of capabilities described in the question:

Concept tested. The core concept being tested is the understanding of the specific capabilities and scope of different Microsoft Defender services, particularly their roles in a security operations center (SOC) context, including threat intelligence, incident response, threat hunting, and vulnerability management.

Reference. https://learn.microsoft.com/en-us/defender/threat-intelligence/microsoft-defender-threat-intelligence-overview

Topics

#Microsoft Defender XDR#security analytics#threat intelligence#incident response

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice