Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Defender for Endpoint (MDE) and Microsoft Sentinel. You need to create an analytics rule in Sentinel that triggers an incident when a device is reported as 'high risk' by MDE. Which data source and rule type should you use?

⚠ Common exam trap

Watch out — candidates often confuse the Microsoft Defender XDR connector (which covers MDE, MDO, MDI, and MDCA) with the Microsoft 365 Defender connector (which is deprecated or used for legacy scenarios), leading candidates to incorrectly choose Option B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender XDR connector with a Scheduled query rule

The Microsoft Defender XDR connector ingests alerts from Microsoft Defender for Endpoint (MDE) into Sentinel. A Scheduled query rule is required to run a KQL query at a defined interval (e.g., every 5 minutes) that checks for devices with a 'high risk' severity level in the ingested alert data. This combination allows you to create an incident when MDE reports a device as high risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Sentinel's Anomalous Activity rule

    Why it's wrong here

    Sentinel's Anomalous Activity rule uses machine learning to baseline normal behavior but has no awareness of Microsoft Defender for Endpoint's device risk score. These rule types inspect ingested telemetry to spot statistical outliers, not the specific RiskScore field that classifies a device as High. Even if MDE data is connected, an anomaly rule will not fire deterministically for the condition DeviceRiskScore == 'High'.

  • ✗

    Microsoft 365 Defender connector with an NRT query rule

    Why it's wrong here

    The Microsoft 365 Defender connector, now superseded by the Microsoft Defender XDR connector, ingests alerts and raw events, but pairing it with an NRT query rule is a weak architectural choice. NRT rules evaluate near-real-time with a one-minute window and restrict certain KQL operators and joins, making them brittle for correlating device identity with a risk score. A scheduled query can reprocess a wider time window and reliably join DeviceInfo to capture the latest risk classification, which NRT cannot guarantee.

  • ✓

    Microsoft Defender XDR connector with a Scheduled query rule

    Why this is correct

    The Microsoft Defender XDR connector brings Microsoft Defender for Endpoint's DeviceInfo table into Sentinel, including fields such as RiskScore and ExposureLevel. Running a Scheduled query rule on that connector lets you use KQL to filter where DeviceRiskScore equals 'High', map entities, and create an incident. This is the supported pattern because scheduled rules allow complex joins, longer time ranges, and robust entity mapping—essential for turning a live risk score into a reliable security alert.

  • ✗

    Microsoft Defender for Cloud connector with a Fusion rule

    Why it's wrong here

    The Microsoft Defender for Cloud connector integrates security alerts from cloud workload protection (VMs, containers, storage) and has no visibility into endpoint devices managed by Microsoft Defender for Endpoint. The Fusion rule engine correlates alerts across connectors to detect multistage attacks; it cannot simply read a single device's RiskScore to decide whether to alert. Querying that connector for endpoint risk fields would fail because the DeviceInfo schema is not present.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.