SC-100 Practice Question: Design solutions that align with security best practices and priorities
Which TWO are best practices for designing a Microsoft 365 Defender (XDR) deployment to ensure optimal detection and response?
⚠ Common exam trap
Watch out — candidates often think enabling all data sources (option D) is unnecessary or could cause noise, but in XDR, comprehensive data ingestion is essential for accurate correlation and detection, while proper tuning and automation handle false positives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure automated investigation and response for common incident types
Option B is correct because configuring automated investigation and response (AIR) for common incident types lets Microsoft 365 Defender automatically investigate and remediate recurring, well-understood threats, which reduces analyst workload and speeds response so human effort can focus on complex attacks. Option D is correct because XDR detection quality depends on ingesting all supported signal sources (endpoint, identity, email, cloud apps, and other connectors) and having the corresponding licenses enabled, since missing telemetry or unlicensed workloads create blind spots that degrade correlation and incident detection. Option A is not a best practice because deploying Defender for Endpoint on unsupported operating systems with limited functionality provides incomplete telemetry and unreliable protection, undermining XDR detection rather than optimizing it. Option C is not a best practice because relying solely on manual alert triage does not scale and increases the risk of missing complex or high-volume attacks that automation and correlation are designed to catch. Option E is not a best practice because configuring workloads in silo mode prevents cross-domain signal correlation, which is the core value of Microsoft 365 Defender XDR and would increase, not reduce, false positives and missed detections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy Defender for Endpoint on unsupported operating systems with limited functionality
Why it's wrong here
Deploying Defender for Endpoint on unsupported operating systems results in a degraded sensor that cannot reliably collect the deep telemetry required for behavioral-based detections. Without vendor support, critical security events may be missed, and the endpoint could become a blind spot that attackers exploit while giving false confidence of coverage. Best practice is to upgrade or replace unsupported platforms rather than accept limited functionality.
- ✓
Configure automated investigation and response for common incident types
Why this is correct
Automated investigation and response (AIR) should be enabled for well-understood incident patterns such as phishing, malware outbreaks, or credential theft, because it allows Microsoft 365 Defender to quarantine files, disable accounts, and contain compromised assets in near real time. This reduces manual burden and shortens attacker dwell time by acting consistently at machine speed. Ensuring AIR runs only for high-confidence, common scenarios also minimizes false-positive disruptions and frees analysts to focus on complex incidents.
- ✗
Rely solely on manual alert triage to avoid missing complex attacks
Why it's wrong here
Relying exclusively on manual alert triage fails to scale, as it quickly leads to security analyst burnout and missed alerts caused by the sheer volume of telemetry in a large M365 environment. Even the most experienced analysts are prone to latency in responding to incidents, and without automation, ransomware and other fast-moving attacks can propagate far beyond the initial ingress point. The appropriate approach is to leverage both automatic and human-led investigation to ensure comprehensive coverage.
- ✓
Enable all supported data sources and ensure proper licensing
Why this is correct
Enabling all supported data sources—such as Microsoft Defender for Identity, Cloud Apps, and Office 365—with the correct E5 licensing ensures that the XDR correlation across signals is both comprehensive and accurate. Gaps in data ingestion or licensing mask suspicious patterns that span multiple workloads, allowing attackers to chain weak signals into a full attack path unnoticed. Proper licensing also grants access to critical APIs/features like advanced hunting and threat analytics, which underpin proactive security operations.
- ✗
Configure each workload (Endpoint, Identity, etc.) in SILO mode to avoid false positives
Why it's wrong here
Configuring each Defender workload in silo mode undermines the core value of Microsoft 365 Defender's XDR correlation, because it prevents signals from multiple sources (for example, an alert from Defender for Identity correlated with a suspicious email) from being fused into one meaningful incident. Threat actors routinely rely on this separation to evade detection, as a single low-severity alert in one workload might never reach analyst attention. Instead, unified incident queues and cross-product pivoting are essential to expose and stop complex attacks.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.