Exam objective

SC-900

Describe threat protection with Microsoft Defender XDR

This objective sits in Describe capabilities of Microsoft security solutions, which carries 38% of the Security, Compliance, and Identity Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe capabilities of Microsoft security solutions

Defender for Endpoint detects a malicious file on a user's device. Defender for Office 365 immediately scans and removes the same file from every mailbox across the organization without manual action. Which Microsoft Defender XDR feature describes this behavior?

Self-healing for compromised devices, user identities, and mailboxesSelf-healing remediates already-impacted assets, like devices, identities, or mailboxes, back to a secure state, but does not describe proactively removing a file before it spreads further.
Combined incidents queue grouping impacted assets into one incidentThe combined incidents queue groups alerts and impacted assets for analyst visibility, it does not itself trigger the cross-product removal action.
Automatic response to threats across the connected Defender productsCorrect · your answerCorrect: real-time signal sharing that instructs another product to act, as in the endpoint-to-mailbox file removal, is automatic response to threats.
Cross-product threat hunting over endpoint, identity, and email dataCross-product threat hunting lets analysts query historic raw signal data, it is an investigative capability, not the automated real-time removal described.
Cross-product single pane of glass in the Defender portal viewThe single pane of glass is a portal view for detections and evidence, not the mechanism that causes the file to be removed from mailboxes.

Correct.

Checked against learn.microsoft.com, July 2026

Concept

Microsoft Defender XDR shares critical threat information in real time between connected products so a detection in one service can trigger a defensive action in another before more damage occurs.

Why C

A malicious file found on an endpoint triggering Defender for Office 365 to scan and remove the same file from all mailboxes is the documented example of automatic response to threats, which stops the progression of an attack across products.

Source

Automatic response to threats - Critical threat information is shared in real time between the Microsoft Defender XDR products to help stop the progression of an attack. For example, if a malicious file is detected on an endpoint protected by Defender for Endpoint, it instructs Defender for Office 365 to scan and remove the file from all e-mail messages.

Microsoft Defender XDR overview, checked July 2026
#defender-xdr#automatic-response#cross-product

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe capabilities of Microsoft security solutions

A security team wants to detect compromised accounts and malicious insider actions against their on-premises Active Directory by analyzing signals collected directly from that directory. Which capability should they deploy?

Sample question 2 of 3

Describe capabilities of Microsoft security solutions

After Microsoft 365's antivirus engine scans an email attachment, a Defender for Office 365 feature opens it in a virtual environment to watch what it does. Which feature is this?

Sample question 3 of 3

Describe capabilities of Microsoft security solutions

An organization suspects staff use unapproved SaaS applications and wants them identified from network traffic and rated against risk indicators. Which Microsoft Defender service does this?

Full Security, Compliance, and Identity Fundamentals question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe capabilities of Microsoft security solutions