Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

An organization uses Microsoft Defender XDR to detect and respond to threats. Which THREE data sources does Defender XDR ingest? (Choose three.)

⚠ Common exam trap

Candidates often confuse Microsoft Sentinel as a data source for Defender XDR, when in reality Sentinel is a SIEM that consumes data from Defender XDR, not the reverse.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Identity

Microsoft Defender XDR is the unified extended detection and response platform that correlates signals from Microsoft's first-party security workloads. Option A, Microsoft Defender for Identity, is correct because it feeds identity-based signals (domain controller sensors, AD FS, Entra ID) into Defender XDR for detecting identity threats like lateral movement and pass-the-hash. Option B, Microsoft Defender for Endpoint, is correct because it supplies endpoint telemetry (device alerts, file/process events) that Defender XDR correlates into incidents. Option D, Microsoft Defender for Office 365, is correct because it contributes email and collaboration signals (phishing, malicious attachments/URLs) to the unified incident queue. Option C, Microsoft Sentinel, is not a native Defender XDR data source; it is a separate SIEM/SOAR that can ingest Defender XDR incidents, not the reverse. Option E, Microsoft Intune, is a device management service and is not one of the Defender XDR native signal sources, even though it integrates with Defender for Endpoint for compliance and onboarding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Defender for Identity

    Why this is correct

    Microsoft Defender for Identity is a cloud-based security solution that monitors on-premises Active Directory and cloud identities, generating signals for identity-based attacks such as pass-the-hash, Kerberoasting, and lateral movement. Its telemetry, including user behavior, logon events, and group policy modifications, is ingested by Microsoft Defender XDR to correlate and enrich incident detection with the identity context that is often central to attacks.

  • ✓

    Microsoft Defender for Endpoint

    Why this is correct

    Microsoft Defender for Endpoint provides endpoint detection and response (EDR) telemetry from Windows, macOS, Linux, and mobile devices. It supplies rich, low-level behavioral signals—file executions, process creation, network connections, memory activities, and the like—that feed Microsoft Defender XDR. These endpoint signals are critical for detecting malware, ransomware, and post-exploitation activities, and they enable automated investigation and response across the entire attack chain.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is wrong because it is a cloud-native SIEM and SOAR platform that ingests logs from many sources, including Defender XDR, rather than being a data source for Defender XDR. Sentinel consumes alerts from Defender XDR for enterprise-wide threat hunting and incident response, but in this context it is a downstream consumer and aggregator, not a provider of raw threat signals to the XDR correlation engine.

  • ✓

    Microsoft Defender for Office 365

    Why this is correct

    Microsoft Defender for Office 365 supplies email and collaboration security signals, including threat intelligence from Exchange Online, SharePoint, OneDrive, and Teams. It detects phishing, malware, malicious URL clicks, and impersonation attacks, and those findings are passed to Microsoft Defender XDR to unify with endpoint and identity events. This makes it an essential data source for investigating attacks that originate via email as the initial access vector.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is a cloud-based endpoint management service for mobile device management (MDM) and mobile application management (MAM), not a threat signal source. It enforces compliance policies, deploys configuration profiles, and manages enrolled devices, but it does not generate attack telemetry or detection data. Intune integrates with Defender XDR for device compliance insights, yet it is not one of the native threat-signal producers like the Defender solution components.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.