Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You need to integrate Microsoft Defender XDR with Microsoft Sentinel for centralized monitoring. Which data connector should you use?

⚠ Common exam trap

A common mix-up: candidates confuse the 'Microsoft 365 Defender connector' (which does not exist) with the 'Microsoft Defender XDR connector', or they mistakenly choose the Defender for Cloud connector thinking it covers all Microsoft security signals.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender XDR connector

The Microsoft Defender XDR connector (option D) is the correct choice because it ingests signals from all Microsoft 365 Defender components—including Defender for Endpoint, Office 365, Identity, and Cloud Apps—into Microsoft Sentinel. This connector uses the Microsoft 365 Defender API to stream unified alerts and incidents, enabling centralized monitoring and correlation across the entire XDR stack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Cloud connector

    Why it's wrong here

    The Microsoft Defender for Cloud connector in Microsoft Sentinel pulls security alerts and posture data from Defender for Cloud, which focuses on cloud workload protection and CSPM across Azure, AWS, and GCP. It does not provide the unified incident feeds or cross-domain correlation from Defender for Endpoint, Defender for Identity, Defender for Office 365, or Defender for Cloud Apps. Selecting this connector would fail to integrate with Microsoft Defender XDR because it only brings in cloud-resource security findings, not the unified incident stream the XDR platform produces.

  • ✗

    Azure Security Center connector

    Why it's wrong here

    Azure Security Center is the former name of the cloud security posture management product now consolidated into Microsoft Defender for Cloud. Its connector ingests Azure resource-level security alerts and regulatory compliance data, rather than the incident telemetry generated by Microsoft 365 workloads. Since the integration requires Microsoft Defender XDR, this connector targets the wrong data source and cannot handle the multi-workload incident reconciliation needed for a true XDR integration.

  • ✗

    Microsoft 365 Defender connector

    Why it's wrong here

    Microsoft 365 Defender is the legacy branding for what is now Microsoft Defender XDR. While the underlying functionality is the same, the connector's current official name in Microsoft Sentinel is 'Microsoft Defender XDR.' Choosing the old name reflects confusion of product branding and is not the accepted connector name for this integration. From a certification perspective, the correct answer must reflect the current product name, so this option is incorrect.

  • ✓

    Microsoft Defender XDR connector

    Why this is correct

    The Microsoft Defender XDR connector is the native Microsoft Sentinel data connector that connects directly to Microsoft Defender XDR through its public API. It ingests incidents, alerts, and advanced hunting event tables from all Microsoft Defender workloads, automatically correlating signals from Endpoint, Identity, Office 365, and Cloud Apps into a Sentinel incident. This bidirectional sync allows incident updates in either portal to propagate to the other, which is exactly what is needed when integrating Microsoft Defender XDR with Microsoft Sentinel.

Go deeper

Related to this question

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.