nerdexam
Microsoft

MS-900 · Question #449

Drag and Drop Question A company plans to use Microsoft 365 Defender. You need to identify the tools that support the Microsoft 365 Defender features. Which tool should you identify? To answer, drag…

The correct answer is Incidents; Advanced hunting; Secure Score. In Microsoft 365 Defender, 'Incidents' is used to correlate and manage related alerts and investigations across the environment, providing a unified view of an attack. 'Advanced Hunting' supports proactive threat hunting using Kusto Query Language (KQL) to query up to 30 days…

Submitted by ricky.ec· Mar 5, 2026Describe the capabilities of Microsoft security solutions – specifically Microsoft 365 Defender services and features (SC-900 / MS-900 Security Domain)

Question

Drag and Drop Question A company plans to use Microsoft 365 Defender. You need to identify the tools that support the Microsoft 365 Defender features. Which tool should you identify? To answer, drag the appropriate tools to the correct features. Each tool may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point. Answer:

Exhibit

MS-900 question #449 exhibit

Answer Area

Drag items

IncidentsThreat analyticsAdvanced huntingSecure Score

Correct arrangement

  • Incidents
  • Advanced hunting
  • Secure Score

Explanation

In Microsoft 365 Defender, 'Incidents' is used to correlate and manage related alerts and investigations across the environment, providing a unified view of an attack. 'Advanced Hunting' supports proactive threat hunting using Kusto Query Language (KQL) to query up to 30 days of raw data across endpoints, emails, identities, and apps. 'Secure Score' measures an organization's security posture and provides recommendations to improve it, acting as a benchmark and improvement tool. 'Threat Analytics' is a valid Microsoft 365 Defender feature as well (used by security analysts to understand active threats), so its exclusion from the correct arrangement suggests the target features in this drag-and-drop map specifically to Incidents, Advanced Hunting, and Secure Score for the described use cases.

Topics

#Microsoft 365 Defender#Threat Protection#Security Operations#Secure Score

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice