SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Which TWO of the following are components of Microsoft Defender XDR (Extended Detection and Response)?
⚠ Common exam trap
It's easy for candidates to confuse Microsoft Sentinel (a SIEM) as part of Defender XDR, but Sentinel is a separate Azure service that can ingest Defender XDR alerts, not a component of the XDR platform itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Endpoint
Microsoft Defender XDR is the unified extended detection and response suite that natively correlates signals across Microsoft's first-party security workloads, and Microsoft Defender for Endpoint (B) is a core component, providing endpoint detection and response (EDR), attack surface reduction, and automated investigation and remediation for devices. Microsoft Defender for Office 365 (C) is likewise a core component, delivering protection and detection for email, collaboration tools, and phishing/URL detonation signals that feed into the XDR incident graph. By contrast, Microsoft Sentinel (A) is a standalone cloud-native SIEM/SOAR platform that, while it can integrate with Defender XDR, is not itself one of its components. Microsoft Intune (D) is a mobile device management (MDM) and endpoint management service, and Microsoft Purview (E) is a data governance, compliance, and information-protection suite — neither is a Defender XDR component.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) solution that provides security analytics and threat intelligence across the enterprise. It acts as a separate, centralized platform that ingests and correlates alerts from multiple sources, including Defender XDR, but it is not itself a component of the Defender XDR suite.
- ✓
Microsoft Defender for Endpoint
Why this is correct
Microsoft Defender for Endpoint is a foundational component of Microsoft Defender XDR (formerly Microsoft 365 Defender). It delivers endpoint detection and response (EDR), vulnerability management, and attack surface reduction capabilities, sharing signals with the unified XDR pipeline to enable cross-domain threat correlation and automated response.
- ✓
Microsoft Defender for Office 365
Why this is correct
Microsoft Defender for Office 365 is indeed a component of Microsoft Defender XDR, safeguarding email and collaboration tools such as Exchange Online, SharePoint, and Teams. It provides threat policies, automated investigation and response, and protection against phishing, malware, and business email compromise, feeding incidents into the XDR console for unified visibility.
- ✗
Microsoft Intune
Why it's wrong here
Microsoft Intune is a cloud-based unified endpoint management (UEM) and mobile device management (MDM) service that manages devices, apps, and compliance policies. While it can integrate with Microsoft Defender for Endpoint to factor device risk into conditional access, Intune itself is not a component of the Defender XDR suite.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview is a comprehensive data governance, risk, and compliance suite that includes information protection, data loss prevention, and insider risk management capabilities. Although it can send signals to Defender XDR and be part of a broader security strategy, Purview is a separate compliance solution and not a core component of Defender XDR.
Go deeper
Related to this question
Learn chapter
Securing Azure IaaS and Containerized Workloads
Key term
XDR Strategy
An XDR strategy is a plan to use extended detection and response tools that collect and analyze data from multiple security layers to stop cyberattacks more effectively.
Key term
SOC Architecture
SOC Architecture is the structured design of people, processes, and technology in a Security Operations Center to detect, analyze, and respond to cyber threats.
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.