Courseiva

MS-900 Microsoft Defender XDR Practice Question

Which FOUR Microsoft 365 services are part of the Microsoft Defender XDR suite?

⚠ Common exam trap

Candidates often mistakenly believe the suite includes only three of these four services or incorrectly include Microsoft Sentinel. In reality, all four Defender components are integral parts of Defender XDR.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Endpoint

Microsoft Defender XDR is the unified extended detection and response suite that natively correlates signals across four Defender workloads. Option A, Microsoft Defender for Endpoint, is correct because it is the endpoint detection and response (EDR) pillar that surfaces device alerts and integrates into the XDR incident queue. Option B, Microsoft Defender for Cloud Apps, is correct because it is the Cloud App Security (CASB) component that feeds SaaS and cloud-app telemetry into Defender XDR. Option D, Microsoft Defender for Office 365, is correct because it protects email, collaboration, and Office apps (phishing, malware, URL detonation) and shares incidents with the suite. Option E, Microsoft Defender for Identity, is correct because it monitors on-premises Active Directory signals (DC sensors) to detect identity-based attacks and is a native XDR pillar. Option C, Microsoft Sentinel, is not part of Defender XDR; it is a separate cloud-native SIEM/SOAR product that can ingest Defender XDR incidents but is licensed and managed independently.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Defender for Endpoint

    Why this is correct

    Microsoft Defender for Endpoint natively shares endpoint telemetry with the other Defender XDR workloads, so correlated incidents and automated investigation appear in a single portal. It satisfies the stem's requirement for a constituent service of the suite, unlike standalone compliance or identity products such as Microsoft Entra ID.

  • ✓

    Microsoft Defender for Cloud Apps

    Why this is correct

    Microsoft Defender for Cloud Apps is a core pillar of Microsoft Defender XDR, delivering SaaS security posture and cloud app threat detection. It feeds signals into the unified incident queue alongside Defender for Endpoint, Office 365 and Identity.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM/SOAR platform, separate from Defender XDR, whose components are Defender for Endpoint, Identity, Office 365 and Cloud Apps. It is tempting because Sentinel ingests Defender signals and correlates incidents, and would be correct for centralised, cross-platform SIEM detection and automation.

  • ✓

    Microsoft Defender for Office 365

    Why this is correct

    Microsoft Defender for Office 365 is one of the four Defender XDR workloads, providing email and collaboration threat protection. It correlates signals with Defender for Endpoint, Identity and Cloud Apps within the unified incident queue.

  • ✓

    Microsoft Defender for Identity

    Why this is correct

    Microsoft Defender for Identity monitors on-premises Active Directory signals, such as suspicious authentication and lateral movement, and feeds them into Microsoft Defender XDR. It is one of the four suite components alongside Defender for Endpoint, Office 365 and Cloud Apps, satisfying the stem's requirement for a genuine XDR service.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MS-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which THREE Microsoft 365 services are part of Microsoft Defender XDR (Extended Detection and Response)? (Select three.)

hard
  • ✓ A.Microsoft Defender for Endpoint
  • B.Microsoft Purview
  • ✓ C.Microsoft Defender for Identity
  • D.Microsoft Sentinel
  • ✓ E.Microsoft Defender for Office 365

Why A: Microsoft Defender XDR (Extended Detection and Response) is a unified security suite that correlates signals across endpoints, identities, and email/collaboration. Microsoft Defender for Endpoint is correct because it provides endpoint detection and response (EDR) capabilities, collecting telemetry from Windows, macOS, Linux, Android, and iOS devices to detect and remediate advanced threats.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.