SC-100 Practice Question: Design solutions that align with security best practices and priorities
Which THREE components are included in Microsoft Defender XDR?
⚠ Common exam trap
Candidates often assume all 'Defender' branded products are automatically part of Microsoft Defender XDR, but Microsoft Defender for IoT and Microsoft Defender for Cloud are separate services that integrate via connectors rather than being core components of the unified XDR suite.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Office 365
Microsoft Defender XDR is the unified extended detection and response suite that correlates signals across Microsoft's first-party security workloads, and its core components include Microsoft Defender for Office 365 (A), which protects email, collaboration tools, and Office apps against phishing, malware, and business email compromise; Microsoft Defender for Identity (C), which monitors on-premises Active Directory Domain Services signals via domain controllers to detect identity-based attacks like lateral movement and credential theft; and Microsoft Defender for Endpoint (D), which provides endpoint detection and response, threat and vulnerability management, and automated investigation on devices. These three feed alerts and incidents into the Defender XDR portal alongside Defender for Cloud Apps to enable cross-domain correlation. Microsoft Defender for IoT (B) is a separate offering for operational technology and IoT/OT environments, and Microsoft Defender for Cloud (E) is a cloud security posture management and workload protection solution (CSPM/CWPP) that, while integrated with the Defender portal, is not one of the three named Defender XDR components tested here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Office 365
Why this is correct
Microsoft Defender for Office 365 is one of the core workload products natively integrated into Microsoft Defender XDR. It protects email and collaboration services such as Exchange Online, SharePoint, Teams, and OneDrive for Business by detecting phishing, malware, malicious links, and business email compromise. Its telemetry is shared with the XDR unified incident engine, enabling cross-domain correlation with endpoint and identity signals for automated investigation and response.
- ✗
Microsoft Defender for IoT
Why it's wrong here
Microsoft Defender for IoT is a standalone security solution for OT and IoT devices, providing asset discovery, continuous monitoring, and threat detection for industrial and unmanaged devices. Although its alerts can be sent to Microsoft Sentinel or other SIEMs, it is not a native component of the Microsoft Defender XDR unified incident pipeline. Unlike the integrated XDR workloads, Defender for IoT does not contribute signals directly to the shared incident queue and therefore is not one of the three correct components.
- ✓
Microsoft Defender for Identity
Why this is correct
Microsoft Defender for Identity is a cloud-based security solution that uses on-premises Active Directory signals to detect advanced identity-based attacks such as Kerberoasting, golden ticket abuse, and lateral movement. It is a first-class component of Defender XDR, feeding identity alerts and contextual data into the unified platform. The XDR correlation engine combines this identity telemetry with endpoint and email data to reconstruct multi-stage attack chains in a single incident.
- ✓
Microsoft Defender for Endpoint
Why this is correct
Microsoft Defender for Endpoint is the endpoint detection and response (EDR) component of Microsoft Defender XDR, delivering continuous device threat monitoring, vulnerability management, and automated response actions. It provides the device-level signals that are essential for XDR correlation, allowing the platform to combine process, network, and file telemetry with identity and email alerts. As a natively integrated workload, it shares investigation evidence and supports automated remediation through the unified Defender XDR console.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is a separate cloud security posture management (CSPM) and cloud workload protection platform (CWPP) for Azure and multi-cloud environments, focused on protecting PaaS, IaaS, and container workloads. While it can be integrated with other security tools and even send alerts to Microsoft Sentinel, it is not a built-in component of Microsoft Defender XDR's unified incident correlation pipeline. Its scope is infrastructure security rather than the identity/endpoint/email signals that constitute the XDR native set, so it is not one of the three correct answers.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.