nerdexam
Microsoft

MS-900 · Question #414

Hotspot Question A company is investigating Microsoft 365 threat protection solutions. You need to identify the services provided by Microsoft Defender. Which services should you identify? To…

This hotspot question tests knowledge of which specific security services are provided under the Microsoft Defender umbrella within Microsoft 365 threat protection solutions.

Submitted by dimitri_ru· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

Hotspot Question A company is investigating Microsoft 365 threat protection solutions. You need to identify the services provided by Microsoft Defender. Which services should you identify? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:

Exhibit

MS-900 question #414 exhibit

Answer Area

  • A platform that collects behavioral telemetry including process, kernel, memory, and registry information.
    Microsoft Defender for EndpointMicrosoft Defender for Office 365Microsoft Defender for IdentityMicrosoft Defender for Cloud Apps
  • A platform that has anti-malware, anti-spam, and anti-spoofing protection.
    Microsoft Defender for EndpointMicrosoft Defender for Office 365Microsoft Defender for IdentityMicrosoft Defender for Cloud Apps
  • A platform that identifies, detects, and investigates advanced threats by using correlated Active Directory signals.
    Microsoft Defender for EndpointMicrosoft Defender for Office 365Microsoft Defender for IdentityMicrosoft Defender for Cloud Apps
  • A platform that allows conditional access policies, log traffic analysis, and API connectors to software hosted by third parties.
    Microsoft Defender for EndpointMicrosoft Defender for Office 365Microsoft Defender for IdentityMicrosoft Defender for Cloud Apps

Explanation

This hotspot question tests knowledge of which specific security services are provided under the Microsoft Defender umbrella within Microsoft 365 threat protection solutions.

Approach. Microsoft Defender encompasses several specialized services: Microsoft Defender for Endpoint (device/endpoint protection and EDR), Microsoft Defender for Office 365 (email and collaboration threat protection including anti-phishing, safe links, safe attachments), Microsoft Defender for Identity (on-premises Active Directory threat detection using signals), Microsoft Defender for Cloud Apps (CASB - Cloud Access Security Broker for SaaS app visibility and control), and Microsoft Defender Vulnerability Management. Services like Azure AD Identity Protection, Microsoft Sentinel (SIEM), and Microsoft Purview (compliance/DLP) are NOT part of the Microsoft Defender family. When evaluating each row in the hotspot, select 'Yes' for any service explicitly branded as 'Microsoft Defender' and 'No' for services that belong to other Microsoft security product families such as Purview, Sentinel, or Entra.

Concept tested. Microsoft Defender product family and its constituent services (Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps) versus other Microsoft 365 security services like Microsoft Sentinel, Microsoft Purview, and Microsoft Entra ID Protection.

Reference. https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-365-defender?view=o365-worldwide

Topics

#Microsoft Defender#Defender for Endpoint#Defender for Office 365#Defender for Identity

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice