nerdexam
Microsoft

MS-900 · Question #385

Hotspot Question Instructions: For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

The correct answer is Microsoft Defender for Identity uses Azure Active Directory to detect and identify compromised identities. = Yes; Microsoft Cloud App Security allows users to identify and combat cyber threats in multiple Microsoft 365 and Azure services. = Yes; Microsoft Defender for Identity protects against malicious threats posed by email messages and web links that are used in collaboration tools. = No. This question assesses the test-taker's understanding of the specific roles and capabilities of Microsoft Defender for Identity, Microsoft Cloud App Security (now Defender for Cloud Apps), and the distinction between Defender for Identity and Defender for Office 365.

Submitted by tom_us· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

Hotspot Question Instructions: For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibit

MS-900 question #385 exhibit

Answer Area

  • Microsoft Defender for Identity uses Azure Active Directory to detect and identify compromised identities.Yes
  • Microsoft Cloud App Security allows users to identify and combat cyber threats in multiple Microsoft 365 and Azure services.Yes
  • Microsoft Defender for Identity protects against malicious threats posed by email messages and web links that are used in collaboration tools.No

Explanation

This question assesses the test-taker's understanding of the specific roles and capabilities of Microsoft Defender for Identity, Microsoft Cloud App Security (now Defender for Cloud Apps), and the distinction between Defender for Identity and Defender for Office 365.

Approach. The correct interaction involves selecting 'Yes' for the first two statements and 'No' for the third statement, based on the following reasoning:

  1. Statement 1: 'Microsoft Defender for Identity uses Azure Active Directory to detect and identify compromised identities.'

    • Selection: Yes
    • Reasoning: Microsoft Defender for Identity (MDI), formerly Azure Advanced Threat Protection (ATP), is specifically designed to protect hybrid identity environments. It monitors Active Directory (on-premises and Azure AD) and other identity sources to detect sophisticated attacks like pass-the-hash, Golden Ticket, and other identity-based threats. Its primary function is indeed to identify and respond to compromised identities by leveraging signals from these directory services.
  2. Statement 2: 'Microsoft Cloud App Security allows users to identify and combat cyber threats in multiple Microsoft 365 and Azure services.'

    • Selection: Yes
    • Reasoning: Microsoft Cloud App Security (MCAS), now known as Microsoft Defender for Cloud Apps (MDCA), is a Cloud Access Security Broker (CASB). It provides deep visibility, control, and threat protection across cloud applications. This includes identifying shadow IT, protecting sensitive data, and detecting anomalies and threats within a wide range of cloud services, notably Microsoft 365 and Azure, as well as third-party cloud apps.
  3. Statement 3: 'Microsoft Defender for Identity protects against malicious threats posed by email messages and web links that are used in collaboration tools.'

    • Selection: No
    • Reasoning: This statement describes a core capability of Microsoft Defender for Office 365 (MDO), not Microsoft Defender for Identity (MDI). MDO specializes in protecting against phishing, spam, malware, malicious URLs, and unsafe attachments across email (Exchange Online) and collaboration tools (SharePoint Online, OneDrive for Business, Microsoft Teams). MDI focuses solely on identity-based threats and attack vectors against Active Directory.

Common mistakes.

  • common_mistake. Common mistakes include confusing the specific functionalities of different Microsoft 365 Defender components. For instance, selecting 'No' for statement 1 would indicate a misunderstanding of MDI's core purpose and its reliance on directory services for identity protection. Selecting 'No' for statement 2 would undervalue the comprehensive threat detection and combat capabilities of MCAS/MDCA across cloud services. The most common mistake for statement 3 would be selecting 'Yes', which indicates a fundamental confusion between Microsoft Defender for Identity (identity protection) and Microsoft Defender for Office 365 (email and collaboration threat protection). Each Defender product has a specialized domain, and misattributing capabilities leads to incorrect answers.

Concept tested. The core concept being tested is a detailed understanding of the individual components within the Microsoft 365 Defender suite, specifically their unique roles, integration points, and the types of threats they are designed to mitigate. This includes knowing the distinct responsibilities of Microsoft Defender for Identity (identity-based threats), Microsoft Defender for Cloud Apps (CASB functionalities across cloud services), and distinguishing these from Microsoft Defender for Office 365 (email and collaboration threats).

Topics

#Microsoft Defender for Identity#Microsoft Cloud App Security#identity protection#threat detection

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice