MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You need to integrate Microsoft Defender XDR with Microsoft Sentinel for centralized monitoring. Which data connector should you use?
⚠ Common exam trap
A common mix-up: candidates confuse the 'Microsoft 365 Defender connector' (which does not exist) with the 'Microsoft Defender XDR connector', or they mistakenly choose the Defender for Cloud connector thinking it covers all Microsoft security signals.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR connector
The Microsoft Defender XDR connector (option D) is the correct choice because it ingests signals from all Microsoft 365 Defender components—including Defender for Endpoint, Office 365, Identity, and Cloud Apps—into Microsoft Sentinel. This connector uses the Microsoft 365 Defender API to stream unified alerts and incidents, enabling centralized monitoring and correlation across the entire XDR stack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud connector
Why it's wrong here
The Microsoft Defender for Cloud connector in Microsoft Sentinel pulls security alerts and posture data from Defender for Cloud, which focuses on cloud workload protection and CSPM across Azure, AWS, and GCP. It does not provide the unified incident feeds or cross-domain correlation from Defender for Endpoint, Defender for Identity, Defender for Office 365, or Defender for Cloud Apps. Selecting this connector would fail to integrate with Microsoft Defender XDR because it only brings in cloud-resource security findings, not the unified incident stream the XDR platform produces.
- ✗
Azure Security Center connector
Why it's wrong here
Azure Security Center is the former name of the cloud security posture management product now consolidated into Microsoft Defender for Cloud. Its connector ingests Azure resource-level security alerts and regulatory compliance data, rather than the incident telemetry generated by Microsoft 365 workloads. Since the integration requires Microsoft Defender XDR, this connector targets the wrong data source and cannot handle the multi-workload incident reconciliation needed for a true XDR integration.
- ✗
Microsoft 365 Defender connector
Why it's wrong here
Microsoft 365 Defender is the legacy branding for what is now Microsoft Defender XDR. While the underlying functionality is the same, the connector's current official name in Microsoft Sentinel is 'Microsoft Defender XDR.' Choosing the old name reflects confusion of product branding and is not the accepted connector name for this integration. From a certification perspective, the correct answer must reflect the current product name, so this option is incorrect.
- ✓
Microsoft Defender XDR connector
Why this is correct
The Microsoft Defender XDR connector is the native Microsoft Sentinel data connector that connects directly to Microsoft Defender XDR through its public API. It ingests incidents, alerts, and advanced hunting event tables from all Microsoft Defender workloads, automatically correlating signals from Endpoint, Identity, Office 365, and Cloud Apps into a Sentinel incident. This bidirectional sync allows incident updates in either portal to propagate to the other, which is exactly what is needed when integrating Microsoft Defender XDR with Microsoft Sentinel.
Go deeper
Related to this question
Learn chapter
Endpoint DLP for Windows Devices
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.