MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Which THREE features are part of Microsoft Defender XDR? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Endpoint
Microsoft Defender XDR is a unified security solution that integrates signals from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, and others. The correct answers are B, C, and E. Option A (Microsoft Purview) is a data governance and compliance solution, not part of Defender XDR. Option D (Microsoft Sentinel) is a separate cloud-native SIEM and SOAR solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview handles data governance, compliance and information protection across data estates; it is not a Defender XDR workload. It tempts because it shares the Microsoft 365 compliance portal and integrates signals with Defender, but its purpose is data security posture, not unified threat detection, prevention and response.
- ✓
Microsoft Defender for Endpoint
Why this is correct
Microsoft Defender for Endpoint contributes endpoint detection and response telemetry into the unified Microsoft Defender XDR portal, correlating device alerts with identity and email signals. It is one of the core workloads natively integrated into Microsoft Defender XDR, satisfying the stem's selection of three features.
- ✓
Microsoft Defender for Office 365
Why this is correct
Microsoft Defender for Office 365 supplies email, collaboration and phishing telemetry into Microsoft Defender XDR, enabling cross-domain incident correlation. It is a native workload of the suite, satisfying the stem's requirement to select three Microsoft Defender XDR features.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM/SOAR product, licensed and deployed separately from Defender XDR's workload suite. It tempts because it ingests Defender signals and appears alongside them in security operations, yet it serves log analytics and orchestration rather than being a native Defender XDR component.
- ✓
Microsoft Defender for Identity
Why this is correct
Microsoft Defender for Identity feeds on-premises Active Directory signals into Microsoft Defender XDR, detecting identity-based attacks such as lateral movement and credential theft. It is a native component of the suite, satisfying the stem's requirement to identify three Microsoft Defender XDR features.
Go deeper
Related to this question
Learn chapter
Defender for Endpoint Deployment via Intune
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.