SC-100 Practice Question: Design security operations, identity, and compliance capabilities
A company wants to monitor and respond to threats across their entire digital estate, including on-premises servers, cloud workloads, and identities. Which Microsoft solution should they use as a central security information and event management (SIEM) and extended detection and response (XDR) platform?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel and Microsoft Defender XDR
Microsoft Sentinel and Microsoft Defender XDR, because Sentinel is Microsoft's cloud-native SIEM that ingests and correlates logs from on-premises servers, cloud workloads, and identities, while Defender XDR provides the extended detection and response layer across endpoints, identities, email, and cloud apps, together forming the central security operations platform the company needs. Microsoft Intune (A) is a mobile device and endpoint management (MDM/MAM) service, not a SIEM/XDR. Microsoft Defender for Cloud (B) is a cloud security posture management (CSPM) and workload protection service, not a central SIEM/XDR. Microsoft Purview (D) is a data governance, compliance, and information protection suite, not a threat monitoring SIEM/XDR platform.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Intune
Why it's wrong here
Microsoft Intune is a cloud-based unified endpoint management (UEM) service that enrolls and manages devices, applies compliance policies, and deploys software updates. It does not ingest security telemetry or provide a queryable log store, so it lacks the SIEM/XDR capabilities needed for continuous monitoring and incident response. While Intune can report device compliance and configuration inventory, it cannot correlate attack patterns or generate security alerts across the environment.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is a Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) that delivers hardening recommendations, vulnerability assessments, and workload-specific threat detection for Azure and hybrid resources. Although it produces individual security alerts, it does not aggregate logs from the entire organization into a central searchable analytics workspace, nor does it offer custom detection rules, incident management, or advanced hunting across all data sources. It is designed to be a data and signal source feeding into Microsoft Sentinel, not a standalone SIEM replacement.
- ✓
Microsoft Sentinel and Microsoft Defender XDR
Why this is correct
Microsoft Sentinel and Microsoft Defender XDR together form a complete monitoring-and-response solution. Sentinel is a cloud-native SIEM that ingests logs from every source, applies analytics rules to detect anomalies, and provides incident management, investigation, and threat hunting, while Microsoft Defender XDR correlates signals across Microsoft Defender for Office 365, Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps. This pairing enables automated response and a single pane of glass for security operations, satisfying the requirement to both monitor and respond to threats across the enterprise.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview is a comprehensive set of data governance, data security, and compliance solutions focused on sensitive data discovery, classification, labeling, and lifecycle management, including features like information protection and eDiscovery. It does not ingest operational security logs or provide the SIEM functions of centralized event correlation, alerting, and case management. While Purview helps protect data at rest and prevent data loss, it cannot deliver the real-time monitoring and incident response workflows across endpoints and identities that the question requires.
Go deeper
Related to this question
Learn chapter
Security Automation and Orchestration with Microsoft Tools
Key term
SOC Architecture
SOC Architecture is the structured design of people, processes, and technology in a Security Operations Center to detect, analyze, and respond to cyber threats.
Key term
XDR Strategy
An XDR strategy is a plan to use extended detection and response tools that collect and analyze data from multiple security layers to stop cyberattacks more effectively.
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.