Exam objective
SC-900Describe threat protection with Microsoft Defender XDR
This objective sits in Describe capabilities of Microsoft security solutions, which carries 38% of the Security, Compliance, and Identity Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
Defender for Endpoint detects a malicious file on a user's device. Defender for Office 365 immediately scans and removes the same file from every mailbox across the organization without manual action. Which Microsoft Defender XDR feature describes this behavior?
Correct.
Checked against learn.microsoft.com, July 2026Concept
Microsoft Defender XDR shares critical threat information in real time between connected products so a detection in one service can trigger a defensive action in another before more damage occurs.
Why C
A malicious file found on an endpoint triggering Defender for Office 365 to scan and remove the same file from all mailboxes is the documented example of automatic response to threats, which stops the progression of an attack across products.
Source
Microsoft Defender XDR overview, checked July 2026Automatic response to threats - Critical threat information is shared in real time between the Microsoft Defender XDR products to help stop the progression of an attack. For example, if a malicious file is detected on an endpoint protected by Defender for Endpoint, it instructs Defender for Office 365 to scan and remove the file from all e-mail messages.
Now you: practice questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
A security team wants to detect compromised accounts and malicious insider actions against their on-premises Active Directory by analyzing signals collected directly from that directory. Which capability should they deploy?
Sample question 2 of 3
After Microsoft 365's antivirus engine scans an email attachment, a Defender for Office 365 feature opens it in a virtual environment to watch what it does. Which feature is this?
Sample question 3 of 3
An organization suspects staff use unapproved SaaS applications and wants them identified from network traffic and rated against risk indicators. Which Microsoft Defender service does this?
Full Security, Compliance, and Identity Fundamentals question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.