Design solutions that align with security best practices and priorities →easyMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design solutions that align with security best practices and priorities
A company wants to use Microsoft Defender XDR to correlate alerts across endpoints, email, and identities. Which component enables this correlation?
⚠ Common exam trap
Candidates often confuse the old branding (Microsoft 365 Defender) with the new branding (Microsoft Defender XDR) and pick the outdated name, or they mistake Microsoft Sentinel's broader SIEM capabilities for the native cross-domain correlation engine that Defender XDR provides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR
Microsoft Defender XDR (the new name for Microsoft 365 Defender) is the unified pre- and post-breach enterprise defense suite that natively correlates signals from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps. Its correlation engine uses machine learning and the Microsoft Intelligent Security Graph to fuse alerts across these domains into a single incident, enabling security teams to see the full attack chain from email to endpoint to identity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft 365 Defender
Why it's wrong here
Microsoft 365 Defender is the retired product name for the unified XDR suite that preceded the current branding. While the underlying correlation engine and incident-generation capabilities are identical, the platform has been officially renamed to Microsoft Defender XDR to emphasize its cross-domain scope. Selecting the legacy terminology is technically inaccurate for current Microsoft documentation and therefore does not satisfy the question as asked.
- ✓
Microsoft Defender XDR
Why this is correct
Microsoft Defender XDR is the correct answer because it is the integrated, cloud-native extended detection and response (XDR) platform that natively correlates alerts from Microsoft Defender for Endpoint, Office 365, Identity, and Cloud Apps. By combining signals across domains into a single incident queue, it performs the automatic cross-product correlation the company requires. Its machine-learning-driven analytics unify threat hunting and response without needing external SIEM logic.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) session that ingests and analyzes telemetry from diverse sources using custom analytics rules. Although it can integrate with Microsoft Defender XDR to enrich correlation and trigger automated responses, it is not the native correlation engine within the Microsoft XDR suite. The question specifically concerns Defender XDR's own correlation, so Sentinel is an external and therefore incorrect choice.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is a cloud workload protection platform (CWPP) that secures resources across Azure, AWS, and GCP, providing posture management, CSPM, and workload-specific threat detection. It focuses on cloud infrastructure threats rather than correlating signals across endpoints, identities, email, and collaboration apps as Defender XDR does. Its alert correlation is scoped to cloud resource telemetry, not the cross-product XDR correlation described in the scenario, making it incorrect.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.