GregLab | Exam Prep

Describe the capabilities of Microsoft security solutions

Microsoft Defender XDR Family

Core

Distinguish the Defender XDR services, their protection domains, threat intelligence, vulnerability management, and portal.

Aligned to the SC-900 skills measured as of July 28, 2026; product behavior verified September 10, 2026.

Why this matters

Cross-domain attacks can move through email, endpoints, identities, and cloud apps. Defender XDR correlates signals while each family member protects a distinct surface.

Must Know

  • Microsoft Defender XDR is an extended detection and response platform that correlates signals, alerts, and incidents across supported Defender services.
  • Microsoft Defender for Office 365 protects collaboration workloads such as email and Microsoft 365 content from threats including phishing and malicious content.
  • Microsoft Defender for Endpoint helps prevent, detect, investigate, and respond to endpoint threats.
  • Microsoft Defender for Cloud Apps provides visibility and control for cloud-app use and helps identify risky cloud behaviors.
  • Microsoft Defender for Identity uses signals associated with on-premises Active Directory identities to detect identity-focused threats.
  • Microsoft Defender Vulnerability Management discovers and prioritizes endpoint vulnerabilities and misconfigurations to reduce exposure.
  • Microsoft Defender Threat Intelligence provides external threat context about actors, infrastructure, indicators, and related internet activity.
  • The Microsoft Defender portal provides a unified security operations experience for incidents, alerts, hunting, reports, assets, and integrated Defender capabilities.

Compare and Distinguish

  • Office 365 vs Endpoint: email/collaboration protection versus device and endpoint protection.
  • Cloud Apps vs Identity: cloud-application visibility and control versus identity threat detection associated with Active Directory.
  • Vulnerability Management vs XDR incident response: reduce exploitable exposure before or alongside attack activity versus correlate and investigate detected attacks.
  • Defender TI vs an internal alert: external threat context and infrastructure research versus evidence generated inside the organization's environment.
  • Defender portal vs a protection service: unified operations surface versus the underlying product capability producing signals.

Scenario examples

  • A phishing message and subsequent endpoint activity are correlated into a broader incident in Defender XDR.
  • A security team identifies unsanctioned cloud-app use with Defender for Cloud Apps.
  • An analyst enriches an indicator with Defender TI while investigating a Defender XDR incident.

Exam traps

  • Defender for Cloud and Defender for Cloud Apps are different products.
  • Defender for Identity is not the same as Microsoft Entra ID Protection.
  • Vulnerability management focuses on exposure and remediation priority, not only active incident correlation.
  • The Defender portal unifies experiences; it does not erase each service's protection boundary.

Key takeaways

  • XDR correlates protection signals across domains.
  • Match each Defender service to email, endpoints, cloud apps, identity, exposure, or external intelligence.
  • Use the Defender portal as the unified operations surface.
  • Do not confuse similarly named Defender products.

Ready for the quiz?

  • Which service protects email and collaboration?
  • Which service finds risky cloud-app use?
  • How does Defender TI differ from Vulnerability Management?

Related objectives

  • D3.4.S1 — Describe Microsoft Defender XDR services
  • D3.4.S2 — Describe Microsoft Defender for Office 365
  • D3.4.S3 — Describe Microsoft Defender for Endpoint
  • D3.4.S4 — Describe Microsoft Defender for Cloud Apps
  • D3.4.S5 — Describe Microsoft Defender for Identity
  • D3.4.S6 — Describe Microsoft Defender Vulnerability Management
  • D3.4.S7 — Describe Microsoft Defender Threat Intelligence (Defender TI)
  • D3.4.S8 — Describe the Microsoft Defender portal

Learn more

Free Microsoft Certified: Security, Compliance, and Identity Fundamentals prep

Build focused SC-900 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

SC-900 at a glance

Level
Beginner / Fundamentals
Duration
45 minutes
Questions
No fixed live question count published
Formats
No guaranteed question-type mix
Scoring
Scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not publish a fixed live question count or guarantee a question-type mix for SC-900. This lane plans only multiple-choice and multiple-response exam-style practice; no supplemental matching, ordering, or case-study exercises are planned. Practice percentages do not reproduce Microsoft's scaled scoring, and difficulty labels describe this site's Fundamentals-level scenario complexity rather than a Microsoft-published question rating.

Reference

SC-900 topics and reference map

Study links

SC-900 resources