SC-100 Practice Question: Design solutions that align with security best practices and priorities
A security architect is designing a solution to detect and respond to advanced threats across email, endpoints, and identities. Which Microsoft security solution should they use?
⚠ Common exam trap
Many candidates confuse Microsoft Sentinel (a SIEM) with Microsoft Defender XDR (an XDR), but Sentinel is a log aggregation and analysis tool requiring manual correlation, while Defender XDR provides native, automated cross-domain detection and response across email, endpoints, and identities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR
Microsoft Defender XDR (Extended Detection and Response) is the correct solution because it provides unified pre- and post-breach detection, investigation, and response across email, endpoints, and identities. It correlates signals from Microsoft Defender for Endpoint, Defender for Office 365, and Defender for Identity into a single incident queue, enabling automated remediation of advanced multi-vector attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview is primarily a data governance and compliance solution, whose core functions are data discovery, classification, sensitive data labeling, and data loss prevention policies. It does not ingest endpoint, email, or identity telemetry for attack detection, and it lacks the detection and automated response engines needed for an XDR platform. Therefore, Purview is incorrectly focused on data management, not threat detection.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automated Response) solution that aggregates logs from numerous sources and uses custom analytics rules for detection. However, it is not an XDR platform because it does not natively integrate endpoint, email, identity, and app defenses into a unified, automated response workflow. Sentinel typically consumes alerts from XDR systems like Microsoft Defender XDR rather than providing the cross-domain, automated containment and remediation that XDR delivers.
- ✓
Microsoft Defender XDR
Why this is correct
Microsoft Defender XDR is the correct choice because it is a true XDR solution that unifies detection, investigation, and response across endpoints, email, identities, applications, and data. It natively collects signals from Microsoft Defender for Endpoint, Office 365, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps, and combines them into a single incident view with automated self-healing actions. This enables security teams to detect and respond to sophisticated multi-stage attacks across the entire attack surface, which is exactly the goal of an XDR architecture.
- ✗
Microsoft Intune
Why it's wrong here
Microsoft Intune is a cloud-based unified endpoint management (UEM) and mobile device management (MDM) solution focused on device configuration, compliance policies, and application deployment. It does not perform threat detection or incident response; it enforces policies such as Conditional Access and can occasionally receive signals about device compliance, but it lacks security analytics, detection sensors, and automated response mechanisms for cyberattacks. Intune is therefore a management tool, not a security detection and response product like an XDR.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.