Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

A company wants to use Microsoft Defender XDR to correlate alerts across endpoints, email, and identities. Which component enables this correlation?

⚠ Common exam trap

Candidates often confuse the old branding (Microsoft 365 Defender) with the new branding (Microsoft Defender XDR) and pick the outdated name, or they mistake Microsoft Sentinel's broader SIEM capabilities for the native cross-domain correlation engine that Defender XDR provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender XDR

Microsoft Defender XDR (the new name for Microsoft 365 Defender) is the unified pre- and post-breach enterprise defense suite that natively correlates signals from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps. Its correlation engine uses machine learning and the Microsoft Intelligent Security Graph to fuse alerts across these domains into a single incident, enabling security teams to see the full attack chain from email to endpoint to identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft 365 Defender

    Why it's wrong here

    Microsoft 365 Defender is the retired product name for the unified XDR suite that preceded the current branding. While the underlying correlation engine and incident-generation capabilities are identical, the platform has been officially renamed to Microsoft Defender XDR to emphasize its cross-domain scope. Selecting the legacy terminology is technically inaccurate for current Microsoft documentation and therefore does not satisfy the question as asked.

  • Microsoft Defender XDR

    Why this is correct

    Microsoft Defender XDR is the correct answer because it is the integrated, cloud-native extended detection and response (XDR) platform that natively correlates alerts from Microsoft Defender for Endpoint, Office 365, Identity, and Cloud Apps. By combining signals across domains into a single incident queue, it performs the automatic cross-product correlation the company requires. Its machine-learning-driven analytics unify threat hunting and response without needing external SIEM logic.

  • Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) session that ingests and analyzes telemetry from diverse sources using custom analytics rules. Although it can integrate with Microsoft Defender XDR to enrich correlation and trigger automated responses, it is not the native correlation engine within the Microsoft XDR suite. The question specifically concerns Defender XDR's own correlation, so Sentinel is an external and therefore incorrect choice.

  • Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud is a cloud workload protection platform (CWPP) that secures resources across Azure, AWS, and GCP, providing posture management, CSPM, and workload-specific threat detection. It focuses on cloud infrastructure threats rather than correlating signals across endpoints, identities, email, and collaboration apps as Defender XDR does. Its alert correlation is scoped to cloud resource telemetry, not the cross-product XDR correlation described in the scenario, making it incorrect.

About these practice questions

This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.