Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Which TWO of the following are benefits of using Microsoft Defender XDR (Extended Detection and Response)? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse the broad capabilities of the Microsoft security portfolio (e.g., Defender for Cloud, Purview) with the specific scope of Defender XDR, leading them to select features that belong to other services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cross-domain correlation of alerts

Option C is correct because Microsoft Defender XDR is specifically designed to correlate signals and alerts across multiple security domains — endpoints (Defender for Endpoint), identities (Defender for Identity), email and collaboration (Defender for Office 365), and cloud apps (Defender for Cloud Apps) — into unified incidents, which is the core value of an XDR platform. Option E is correct because Defender XDR includes automated investigation and response (AIR) capabilities that use playbooks and automation to investigate alerts, remediate threats, and reduce analyst workload. Option A is not correct because vulnerability scanning of VMs is a function of Microsoft Defender for Cloud (or Defender Vulnerability Management), not the defining benefit of Defender XDR. Option B is not correct because compliance assessments are provided by Microsoft Purview Compliance Manager and Microsoft Defender for Cloud regulatory compliance dashboards, not by Defender XDR itself. Option D is not correct because Defender XDR is a detection and response platform and does not replace a network firewall, which remains necessary for perimeter and network-layer filtering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Scans for vulnerabilities in VMs

    Why it's wrong here

    Vulnerability scanning for VMs is a workload protection capability of Microsoft Defender for Cloud, which assesses Azure and hybrid workloads for missing patches, misconfigurations, and known CVEs. Microsoft Defender XDR, by contrast, focuses on cross-domain detection and response across endpoints, identities, email, and cloud apps rather than infrastructure vulnerability assessment. Therefore, this is not a benefit of Defender XDR.

  • ✗

    Provides compliance assessments

    Why it's wrong here

    Compliance assessments, such as regulatory standards like ISO 27001 or HIPAA, are delivered through Microsoft Purview Compliance Manager and Defender for Cloud's regulatory compliance dashboard. Defender XDR does not generate compliance scores or map controls to regulations; it concentrates on incident correlation and automated threat response. Thus, attributing compliance assessments to Defender XDR is incorrect.

  • ✓

    Cross-domain correlation of alerts

    Why this is correct

    Cross-domain correlation of alerts is a core benefit of Microsoft Defender XDR because it ingests signals from Microsoft Defender for Endpoint, Identity, Office 365, and Cloud Apps, and fuses them into a unified incident. This correlation enables security teams to see the full attack chain—such as a phishing email leading to credential theft and lateral movement—rather than investigating disjointed alerts. This is exactly the value that differentiates XDR from single-vector security tools.

  • ✗

    Replaces the need for a firewall

    Why it's wrong here

    Defender XDR does not replace network firewalls because it operates at the endpoint and identity layers, detecting and responding to threats after they occur, not filtering network traffic. Firewalls are preventive network controls that block unauthorized traffic at the network perimeter and between segments. Defender XDR complements, but never substitutes, network security appliances.

  • ✓

    Automated investigation and response

    Why this is correct

    Automated investigation and response (AIR) is a native feature of Defender XDR that uses AI playbooks to automatically investigate alerts, contain compromised assets, and remediate threats—such as isolating an endpoint or disabling a compromised account. This reduces mean time to respond and lessens the load on SOC analysts by handling repeatable threat scenarios. It is a defining benefit of the XDR platform.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.