Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

A company wants to monitor and respond to threats across their entire digital estate, including on-premises servers, cloud workloads, and identities. Which Microsoft solution should they use as a central security information and event management (SIEM) and extended detection and response (XDR) platform?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Sentinel and Microsoft Defender XDR

Microsoft Sentinel and Microsoft Defender XDR, because Sentinel is Microsoft's cloud-native SIEM that ingests and correlates logs from on-premises servers, cloud workloads, and identities, while Defender XDR provides the extended detection and response layer across endpoints, identities, email, and cloud apps, together forming the central security operations platform the company needs. Microsoft Intune (A) is a mobile device and endpoint management (MDM/MAM) service, not a SIEM/XDR. Microsoft Defender for Cloud (B) is a cloud security posture management (CSPM) and workload protection service, not a central SIEM/XDR. Microsoft Purview (D) is a data governance, compliance, and information protection suite, not a threat monitoring SIEM/XDR platform.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is a cloud-based unified endpoint management (UEM) service that enrolls and manages devices, applies compliance policies, and deploys software updates. It does not ingest security telemetry or provide a queryable log store, so it lacks the SIEM/XDR capabilities needed for continuous monitoring and incident response. While Intune can report device compliance and configuration inventory, it cannot correlate attack patterns or generate security alerts across the environment.

  • ✗

    Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud is a Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) that delivers hardening recommendations, vulnerability assessments, and workload-specific threat detection for Azure and hybrid resources. Although it produces individual security alerts, it does not aggregate logs from the entire organization into a central searchable analytics workspace, nor does it offer custom detection rules, incident management, or advanced hunting across all data sources. It is designed to be a data and signal source feeding into Microsoft Sentinel, not a standalone SIEM replacement.

  • ✓

    Microsoft Sentinel and Microsoft Defender XDR

    Why this is correct

    Microsoft Sentinel and Microsoft Defender XDR together form a complete monitoring-and-response solution. Sentinel is a cloud-native SIEM that ingests logs from every source, applies analytics rules to detect anomalies, and provides incident management, investigation, and threat hunting, while Microsoft Defender XDR correlates signals across Microsoft Defender for Office 365, Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps. This pairing enables automated response and a single pane of glass for security operations, satisfying the requirement to both monitor and respond to threats across the enterprise.

  • ✗

    Microsoft Purview

    Why it's wrong here

    Microsoft Purview is a comprehensive set of data governance, data security, and compliance solutions focused on sensitive data discovery, classification, labeling, and lifecycle management, including features like information protection and eDiscovery. It does not ingest operational security logs or provide the SIEM functions of centralized event correlation, alerting, and case management. While Purview helps protect data at rest and prevent data loss, it cannot deliver the real-time monitoring and incident response workflows across endpoints and identities that the question requires.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.