nerdexam
Microsoft

MS-900 · Question #458

Hotspot Question A company plans to implement Microsoft Defender XDR. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is…

This hotspot question tests knowledge of Microsoft Defender XDR capabilities, including its components, integration points, and core functionality for unified security operations.

Submitted by femi9· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

Hotspot Question A company plans to implement Microsoft Defender XDR. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibit

MS-900 question #458 exhibit

Answer Area

  • Conditional Access App Control integrates Microsoft and third-party cloud apps to enforce policies, detect threats, and provide governance actions to resolve issues.
  • Microsoft Secure Score provides real-time visibility and control over access and activities within cloud apps.
  • The Cloud Access Security Broker monitors user activities for anomalous behaviors and controls access to resources through access controls.

Explanation

This hotspot question tests knowledge of Microsoft Defender XDR capabilities, including its components, integration points, and core functionality for unified security operations.

Approach. To answer hotspot questions about Microsoft Defender XDR, you must understand that it is a unified pre- and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints (Defender for Endpoint), identities (Defender for Identity), email (Defender for Office 365), cloud apps (Defender for Cloud Apps), and more. Key facts: Defender XDR correlates signals across these workloads into unified incidents, supports automated investigation and remediation (AIR), integrates with Microsoft Sentinel as an SIEM layer, provides a unified portal at security.microsoft.com, and uses AI/ML to reduce alert fatigue. Statements that align with these capabilities should be marked Yes; those that misrepresent scope, integration, or functionality should be marked No.

Concept tested. Microsoft Defender XDR architecture, component integration (Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps), unified incident management, automated investigation and response (AIR), and the scope of cross-domain threat protection.

Reference. https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-365-defender?view=o365-worldwide

Topics

#Microsoft Defender XDR#Cloud Access Security Broker#Secure Score#Conditional Access App Control

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice