Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You need to design a unified security operations platform. Which THREE capabilities should you enable?

⚠ Common exam trap

Candidates often confuse Azure Policy (a compliance tool) or Purview Information Protection (a data protection tool) with core security operations capabilities, when the question specifically asks for capabilities that unify detection and response across a SIEM and XDR platform.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender XDR incident integration with Sentinel

Option C is correct because integrating Microsoft Defender XDR incidents with Microsoft Sentinel streams correlated alerts and incidents from Defender XDR products (Defender for Endpoint, Identity, Office 365, Cloud Apps) into Sentinel, enabling a single incident queue and unified investigation across the SOC. Option D is correct because Microsoft Sentinel provides the cloud-native SIEM layer—log ingestion via data connectors, analytics rules, and KQL-based hunting—that serves as the central platform for the unified security operations design. Option E is correct because Sentinel UEBA builds behavioral baselines and entity pages (users, hosts, IPs) that surface anomalous activity and enrich incidents, which is essential for detecting threats that static rules miss in a unified SOC. Option A is not correct here because Azure Policy governs resource compliance and configuration, not security operations incident detection or response. Option B is not correct because Microsoft Purview Information Protection focuses on data classification, labeling, and DLP, which is a data-governance capability rather than a SIEM/XDR operations capability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Policy for security controls

    Why it's wrong here

    Azure Policy is a governance service that evaluates and enforces rules for Azure resource configurations, such as requiring encryption, defining allowed regions, or adding tags. It is a control-plane compliance tool, not a security operations platform, and it cannot ingest security logs, correlate alerts, or manage incidents. Therefore, it is incorrect because it addresses preventive infrastructure compliance rather than the detection and response workflows needed to unify incidents in Sentinel.

  • ✗

    Microsoft Purview Information Protection

    Why it's wrong here

    Microsoft Purview Information Protection is focused on data classification, labeling, and encryption to safeguard sensitive information across files, emails, and other data stores. While it contributes to an organization's overall security posture, it does not provide detection, investigation, or response capabilities, nor does it integrate with Sentinel for incident correlation. It is wrong because it is a data governance and protection service, not a security operations platform for unified incident management.

  • ✓

    Microsoft Defender XDR incident integration with Sentinel

    Why this is correct

    The Microsoft Defender XDR incident integration is the correct answer because it connects Microsoft 365 Defender (covering endpoints, identities, email, and cloud apps) directly to Sentinel, pulling in pre-correlated incidents rather than raw alerts. This integration provides a single queue for security operations, enables bidirectional incident synchronization (status changes propagate both ways), and allows analysts to leverage Sentinel's SOAR actions across Defender XDR incidents. Without this integration, defenders would need to juggle multiple portals, losing the unified visibility that the question requires.

  • ✓

    Microsoft Sentinel SIEM

    Why this is correct

    Microsoft Sentinel, as a cloud-native SIEM, is audibly correct for the overall security operations platform because it ingests logs from heterogeneous sources, normalizes them, and applies analytics rules to produce alerts and incidents. However, the question specifically asks about unifying Microsoft Defender XDR incidents into Sentinel, which is achieved by the dedicated Defender XDR incident connector rather than the SIEM capabilities alone. Sentinel SIEM is a prerequisite, but it is not the specific mechanism that brings Defender XDR's correlational incident data into a single console.

  • ✓

    Microsoft Sentinel UEBA (User and Entity Behavior Analytics)

    Why this is correct

    UEBA in Sentinel leverages machine learning models on built-in and custom entities to establish behavioral baselines for users, hosts, and applications, detecting anomalies like impossible travel, lateral movement, or resource access spikes. While this is a valuable detection layer for identifying insider threats and compromised accounts, it is an analytics module that operates on log data within Sentinel. It is correct in the sense of being part of Sentinel's advanced detection capabilities, but it does not provide the cross-domain incident integration from Defender XDR that the question targets, so it is not the right answer in this context.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.