Courseiva

SC-200 Manage a security operations environment Practice Question

Which THREE components are part of Microsoft Defender XDR? (Select three.)

⚠ Common exam trap

Many candidates confuse Microsoft Entra ID (formerly Azure AD) as a security detection component because it handles identity, but it is not a source of threat alerts within Defender XDR; instead, it is the identity provider that Defender for Identity monitors for malicious activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Endpoint

Microsoft Defender XDR is the unified extended detection and response suite that correlates signals across Microsoft's first-party security workloads, and its core components include Microsoft Defender for Endpoint (A), which provides endpoint detection and response (EDR) for devices; Microsoft Defender for Identity (C), which monitors on-premises Active Directory Domain Services signals via sensors to detect identity-based attacks; and Microsoft Defender for Office 365 (E), which protects email, collaboration, and Office apps against phishing, malware, and business email compromise. These three services natively share incidents, alerts, and advanced hunting data in the Microsoft 365 Defender portal, which is why they are part of Defender XDR. Microsoft Entra ID (B) is the identity and access management service (formerly Azure AD) and is not itself a Defender XDR workload, though it feeds identity signals into the suite. Microsoft Defender for Cloud (D) is a cloud security posture management and workload protection offering for Azure, multicloud, and hybrid resources, and it belongs to the Microsoft Defender for Cloud family rather than being one of the Defender XDR components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Defender for Endpoint

    Why this is correct

    Microsoft Defender for Endpoint is one of the core workloads that compose Microsoft Defender XDR, feeding endpoint detections and alerts into the unified incident queue. Its signals correlate with the other Defender services, making it a required component of the suite.

  • ✗

    Microsoft Entra ID

    Why it's wrong here

    Microsoft Entra ID is an identity and access management service, not a Defender XDR workload; the suite comprises Defender for Endpoint, Identity, Office 365, Cloud Apps, and Vulnerability Management. It is tempting because Defender for Identity draws signals from Entra ID, but Entra ID itself sits outside the XDR component list.

  • ✓

    Microsoft Defender for Identity

    Why this is correct

    Microsoft Defender for Identity is a core Microsoft Defender XDR workload, surfacing identity-based detections from on-premises Active Directory signals. Those alerts correlate into the unified incident queue alongside endpoint, email and cloud app data, making it a required component of the suite.

  • ✗

    Microsoft Defender for Cloud

    Why it's wrong here

    Defender for Cloud protects cloud workloads via posture management and workload protection; it sits outside the Defender XDR suite, which comprises Defender for Endpoint, Identity, Office 365 and Cloud Apps. It is tempting because of the shared Defender branding, but it is a separate CNAPP product.

  • ✓

    Microsoft Defender for Office 365

    Why this is correct

    Microsoft Defender for Office 365 is a core Microsoft Defender XDR workload, delivering email and collaboration threat detections. Its alerts correlate with endpoint, identity and cloud app signals in the unified incident queue, making it a required component of the suite.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.