Design solutions that align with security best practices and priorities →easyMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design solutions that align with security best practices and priorities
You are designing a security operations strategy for Microsoft 365. You need to prioritize alerts from Microsoft Defender XDR based on their impact on business operations. Which security best practice should you follow?
⚠ Common exam trap
Watch out — candidates often choose Option D because MITRE ATT&CK is a common framework in security operations, but they overlook that Microsoft Defender XDR's prioritization engine uses a multi-faceted risk assessment (including asset criticality and business impact) rather than a single technique-based filter.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prioritize alerts based on a risk assessment that considers asset criticality, threat severity, and business impact
Microsoft Defender XDR integrates with Microsoft 365 Defender's risk-based alert prioritization, which uses a combination of asset criticality (e.g., from Microsoft Purview or Defender for Cloud Apps), threat severity (e.g., from the Microsoft Defender portal's alert severity levels: Informational, Low, Medium, High), and business impact (e.g., via sensitivity labels or data classification). This aligns with the security best practice of risk-based alert triage, ensuring that high-impact alerts are addressed first to minimize business disruption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Prioritize alerts based on a risk assessment that considers asset criticality, threat severity, and business impact
Why this is correct
Risk-based prioritization that scores asset criticality, threat severity, and business impact is the industry-standard approach because it translates raw signals into actionable decisions aligned with organizational value. By quantifying each alert's potential damage against the importance of the affected system, security operations teams can focus containment and investigation resources on events most likely to cause significant harm. This method also supports continuous improvement by allowing thresholds to be tuned based on telemetry and incident outcomes.
- ✗
Prioritize alerts based on a qualitative risk assessment only
Why it's wrong here
A purely qualitative risk assessment relies on subjective judgment using categories like 'high,' 'medium,' or 'low' without consistent numerical or statistical grounding. This introduces analyst bias, makes prioritization difficult to reproduce across shifts, and frustrates objective communication to leadership or auditors. Without defined scoring criteria for asset value, threat likelihood, and exploitability, two analysts will often assign different urgency levels to the same alert, leading to inconsistent response times.
- ✗
Treat all alerts with equal severity to ensure none are missed
Why it's wrong here
Treating every alert as equal severity creates alert fatigue, a well-documented operational failure in SOCs where analysts become desensitized to a flood of notifications and start ignoring or triaging slowly. This approach drains limited human attention on low-fidelity or benign activity while true critical incidents hide in the noise, eventually increasing mean time to respond and detect. It also disables tiered escalation, SLA enforcement, and automation orchestration, all of which depend on differentiated priority levels.
- ✗
Prioritize alerts based solely on the MITRE ATT&CK technique involved
Why it's wrong here
Prioritizing solely by the MITRE ATT&CK technique used ignores the environment- and asset-specific impact that determines whether a technique is actually dangerous. A technique like PowerShell execution is trivial on a development sandbox but catastrophic on a domain controller, yet technique-only scoring treats both identically. It also omits compensating controls, exploitability, threat actor intent, and business criticality, so the SOC cannot distinguish opportunistic commodity activity from a targeted attack against crown-jewel assets.
Go deeper
Related to this question
About these practice questions
One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.