Objective defender.xdrSC-900

Describe threat protection with Microsoft Defender XDR

Objective defender.xdr sits in Describe capabilities of Microsoft security solutions, which carries 38% of the SCI Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe capabilities of Microsoft security solutionsModerate

A security team wants sign-ins flagged as medium or high risk to automatically require multifactor authentication, with the risk detected and reported by the same service. Which action addresses this?

Correct.

The concept

The scenario names two jobs that must land in the same service: something has to calculate that a sign-in is probably compromised, and something has to change the access outcome when it does. Several identity capabilities do one or the other. Credential issuance, entitlement lifecycle, legacy directory protocols and workload identity all sit outside that pairing.

Why this answer

Microsoft Entra ID Protection both calculates the sign-in risk level and exposes it as a Conditional Access condition, so one service covers detection and the automatic multifactor challenge. The other capabilities listed each handle a different part of identity and cannot score a sign-in at all.

  • AEntra ID Governance automates access requests, assignments, and reviews for lifecycle management, not sign-in risk detection.
  • BEntra Verified ID issues and verifies digital credentials such as diplomas, unrelated to sign-in risk scoring.
  • Correct: detection and enforcement live in one service here.
  • DEntra Workload ID manages authentication for applications and services, not interactive user sign-in risk.
  • EEntra Domain Services provides managed Kerberos, NTLM, and LDAP for legacy apps, not risk-based policy enforcement.
Read the sourceMicrosoft Learn: What is Microsoft Entra ID
Verified against learn.microsoft.com · 2026-07-28
entra-id-protectionconditional-accessrisk-based-policythreat-protection

Now you: objective defender.xdr questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe capabilities of Microsoft security solutionsHard

A user holds the Contributor role at a subscription scope, but a deny assignment blocks write actions on one resource group. The user's sign-in is flagged high risk, and they satisfy a risk-based Conditional Access policy requiring MFA. They then try to create a resource in that resource group. What happens?

Sample question 2 of 3

Describe capabilities of Microsoft security solutionsModerate

A security team wants sign-ins scored as medium or high risk to automatically require multifactor authentication before access is granted. Which Microsoft Entra capability provides this risk-based detection?

Sample question 3 of 3

Describe capabilities of Microsoft security solutionsModerate

A phishing message leads to a malicious sign-in and then to activity on a laptop. Which capability stitches those three signals into one incident?

Full SCI Fundamentals question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe capabilities of Microsoft security solutions