Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Which TWO components are part of Microsoft Defender XDR?

⚠ Common exam trap

MS-102 often tests whether candidates confuse Defender XDR components with adjacent Microsoft security and compliance products like Purview, Intune, and Sentinel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Office 365

Microsoft Defender XDR is a unified extended detection and response suite that natively correlates signals across Microsoft's first-party security workloads, and Microsoft Defender for Office 365 (option A) is one of its core pillars, delivering protection against phishing, malware, and business email compromise across Exchange Online, Teams, and SharePoint/OneDrive. Microsoft Defender for Endpoint (option C) is likewise a native Defender XDR component, providing endpoint detection and response, attack surface reduction, and automated investigation and remediation that feed into the unified incident queue. By contrast, Microsoft Purview (option B) is a separate compliance and data-governance solution family (information protection, DLP, eDiscovery), Microsoft Intune (option D) is the cloud-based endpoint management/MDM service in the Microsoft Intune family, and Microsoft Sentinel (option E) is a standalone cloud-native SIEM/SOAR product that integrates with Defender XDR but is not itself one of its constituent workloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Defender for Office 365

    Why this is correct

    Microsoft Defender for Office 365 is one of the workload pillars composing Microsoft Defender XDR, feeding email, collaboration and phishing signals into the unified incident graph. Its native integration with Defender for Endpoint, Identity and Cloud Apps satisfies the stem's requirement for a constituent component of the suite.

  • ✗

    Microsoft Purview

    Why it's wrong here

    Microsoft Purview governs data classification, sensitivity labels, DLP and compliance, not cross-domain attack detection. It is tempting because Purview and Defender share signals around sensitive data exposure, but Defender XDR's components are Defender for Endpoint, Identity, Office 365, Cloud Apps and Vulnerability Management.

  • ✓

    Microsoft Defender for Endpoint

    Why this is correct

    Microsoft Defender for Endpoint is a core Microsoft Defender XDR workload, feeding endpoint detection and response signals into the unified incident queue. It satisfies the stem's requirement by being natively integrated into the XDR suite, correlating endpoint alerts with identity, email and cloud app telemetry for cross-domain attack disruption.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune handles endpoint configuration, compliance policy and app deployment, not threat detection or incident correlation. It is tempting because device compliance signals feed Defender for Endpoint's risk scoring, yet Intune sits in the management plane, while Defender XDR comprises Defender for Endpoint, Identity, Office 365, Cloud Apps and Vulnerability Management.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM and SOAR platform, separate from Defender XDR, though it ingests Defender incidents through connectors. It is tempting because both surface security incidents in one portal, but Defender XDR's components are Defender for Endpoint, Identity, Office 365, Cloud Apps and Vulnerability Management.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.