Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Which TWO Microsoft security solutions should be integrated to provide a comprehensive Zero Trust architecture that includes identity protection, endpoint detection, and response? (Select exactly two correct options.)

⚠ Common exam trap

It's easy for candidates to confuse Microsoft 365 E5 (a licensing bundle) with a specific security solution, or they mistakenly think Microsoft Sentinel (a SIEM) fulfills the endpoint detection requirement, when in fact Sentinel is for log analysis and not for real-time endpoint detection and response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender XDR

Microsoft Defender XDR (B) is correct because it is the extended detection and response platform that unifies signals across endpoints (Defender for Endpoint), identities (Defender for Identity), email and collaboration (Defender for Office 365), and cloud apps (Defender for Cloud Apps), delivering automated endpoint detection and response capabilities required by the scenario. Microsoft Entra ID (C) is correct because it provides the identity protection pillar of Zero Trust, including Conditional Access, risk-based sign-in and user risk detection via Entra ID Protection, and phishing-resistant authentication such as FIDO2 and Windows Hello for Business. Together, Entra ID secures and verifies identities while Defender XDR detects, investigates, and responds to threats across endpoints and other workloads, satisfying the identity protection plus endpoint detection and response requirement. Microsoft 365 E5 (A) is a licensing bundle rather than a distinct security solution, so it does not itself constitute the integration of identity protection and XDR. Microsoft Sentinel (D) is a SIEM/SOAR platform for centralized log ingestion and orchestration, not the endpoint detection and response engine, and Microsoft Purview (E) focuses on data governance, compliance, and information protection rather than identity or endpoint threat response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft 365 E5

    Why it's wrong here

    Microsoft 365 E5 is a commercial licensing bundle, not an operational security solution. Although it includes licenses for Defender, Sentinel, and other components, it does not provide any security telemetry or enforcement capability of its own. Since the question asks which solutions to integrate, E5 is a procurement vehicle rather than a system to integrate.

  • ✓

    Microsoft Defender XDR

    Why this is correct

    Microsoft Defender XDR is a core security solution because it correlates signals across endpoints, email, identities, and cloud apps, enabling extended detection and response. In a Zero Trust architecture, it serves as the enforcement and detection plane that consumes identity and endpoint telemetry. Integrating it with Entra ID lets suspicious identity behavior trigger automated response actions such as blocking a sign-in.

  • ✓

    Microsoft Entra ID

    Why this is correct

    Microsoft Entra ID is the essential identity and access management layer, providing conditional access, MFA, and identity protection. Zero Trust explicitly treats identity as the primary security perimeter, so Entra ID is a foundational component. Its integration with Defender XDR allows identity risk events to be shared in real time, closing the loop between detection and access enforcement.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM and SOAR platform that aggregates logs and analytics from many sources. It is valuable for managing security incidents but does not itself perform access enforcement or endpoint protection, so it is not one of the two fundamental Zero Trust integration points. Placing Sentinel above XDR and Entra ID adds monitoring but does not replace their control-plane roles.

  • ✗

    Microsoft Purview

    Why it's wrong here

    Microsoft Purview focuses on data governance, compliance, and information protection, including sensitivity labels and data loss prevention. While it helps classify data, it is not a Zero Trust enforcement component because it does not grant or deny access to resources based on user, device, or location. The core Zero Trust integration pair must include identity and endpoint threat protection, not data compliance tooling.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.