SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Defender for Endpoint (MDE) and Microsoft Sentinel. You need to create an analytics rule in Sentinel that triggers an incident when a device is reported as 'high risk' by MDE. Which data source and rule type should you use?
⚠ Common exam trap
Watch out — candidates often confuse the Microsoft Defender XDR connector (which covers MDE, MDO, MDI, and MDCA) with the Microsoft 365 Defender connector (which is deprecated or used for legacy scenarios), leading candidates to incorrectly choose Option B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR connector with a Scheduled query rule
The Microsoft Defender XDR connector ingests alerts from Microsoft Defender for Endpoint (MDE) into Sentinel. A Scheduled query rule is required to run a KQL query at a defined interval (e.g., every 5 minutes) that checks for devices with a 'high risk' severity level in the ingested alert data. This combination allows you to create an incident when MDE reports a device as high risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Sentinel's Anomalous Activity rule
Why it's wrong here
Sentinel's Anomalous Activity rule uses machine learning to baseline normal behavior but has no awareness of Microsoft Defender for Endpoint's device risk score. These rule types inspect ingested telemetry to spot statistical outliers, not the specific RiskScore field that classifies a device as High. Even if MDE data is connected, an anomaly rule will not fire deterministically for the condition DeviceRiskScore == 'High'.
- ✗
Microsoft 365 Defender connector with an NRT query rule
Why it's wrong here
The Microsoft 365 Defender connector, now superseded by the Microsoft Defender XDR connector, ingests alerts and raw events, but pairing it with an NRT query rule is a weak architectural choice. NRT rules evaluate near-real-time with a one-minute window and restrict certain KQL operators and joins, making them brittle for correlating device identity with a risk score. A scheduled query can reprocess a wider time window and reliably join DeviceInfo to capture the latest risk classification, which NRT cannot guarantee.
- ✓
Microsoft Defender XDR connector with a Scheduled query rule
Why this is correct
The Microsoft Defender XDR connector brings Microsoft Defender for Endpoint's DeviceInfo table into Sentinel, including fields such as RiskScore and ExposureLevel. Running a Scheduled query rule on that connector lets you use KQL to filter where DeviceRiskScore equals 'High', map entities, and create an incident. This is the supported pattern because scheduled rules allow complex joins, longer time ranges, and robust entity mapping—essential for turning a live risk score into a reliable security alert.
- ✗
Microsoft Defender for Cloud connector with a Fusion rule
Why it's wrong here
The Microsoft Defender for Cloud connector integrates security alerts from cloud workload protection (VMs, containers, storage) and has no visibility into endpoint devices managed by Microsoft Defender for Endpoint. The Fusion rule engine correlates alerts across connectors to detect multistage attacks; it cannot simply read a single device's RiskScore to decide whether to alert. Querying that connector for endpoint risk fields would fail because the DeviceInfo schema is not present.
Go deeper
Related to this question
Learn chapter
Governance, Risk, and Compliance Strategy Design
Key term
XDR Strategy
An XDR strategy is a plan to use extended detection and response tools that collect and analyze data from multiple security layers to stop cyberattacks more effectively.
Key term
SOC Architecture
SOC Architecture is the structured design of people, processes, and technology in a Security Operations Center to detect, analyze, and respond to cyber threats.
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.