Courseiva

SC-200 Manage a security operations environment Practice Question

Which THREE components are part of Microsoft's unified security operations platform (Microsoft Defender XDR)?

⚠ Common exam trap

It's easy for candidates to confuse Microsoft Sentinel as a component of Microsoft Defender XDR, when in fact Sentinel is a separate SIEM that can ingest data from Defender XDR but is not part of the unified platform itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Endpoint.

Microsoft Defender XDR is Microsoft's unified security operations platform that integrates signals from across the Microsoft 365 ecosystem. Microsoft Defender for Endpoint is a core component, providing endpoint detection and response (EDR) capabilities, including behavioral-based detection, automated investigation, and threat hunting on Windows, macOS, Linux, Android, and iOS devices. It contributes telemetry such as process creation, network connections, and file events to the unified incident and alert correlation in the Defender XDR portal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Defender for Endpoint.

    Why this is correct

    Microsoft Defender for Endpoint is a core workload in Microsoft Defender XDR, providing endpoint detection and response (EDR), vulnerability management, and attack surface reduction. It ingests signals from endpoints and correlates them with other Defender workloads to enable automated investigation and remediation. As one of the three correct choices, it is a native component of the unified security operations platform.

  • ✗

    Microsoft Intune.

    Why it's wrong here

    Microsoft Intune is a cloud-based unified endpoint management (UEM) and mobile device management (MDM) service, focused on device configuration, compliance, and app deployment. It does not provide threat detection, incident response, or security analytics, and it is not a workload within Microsoft Defender XDR. While it can integrate with Defender for Endpoint for conditional access, it is a management tool rather than a security component of the unified platform.

  • ✓

    Microsoft Defender for Office 365.

    Why this is correct

    Microsoft Defender for Office 365 protects email and collaboration workloads such as Exchange Online, SharePoint Online, and Teams. It is a native Defender XDR workload that delivers threat intelligence, safe attachments/links, and automated investigation in mailboxes. Its alerts and signals are shared across the unified platform to enable cross-domain attack correlation, making it one of the three correct components.

  • ✓

    Microsoft Defender for Identity.

    Why this is correct

    Microsoft Defender for Identity is a cloud-based identity protection solution that monitors on-premises Active Directory and cloud identities for suspicious behavior. It detects attacks such as pass-the-hash, lateral movement, and privilege escalation by analyzing domain controller and identity provider signals. As a Defender XDR workload, it feeds its alerts into the unified incident queue, making it a correct component of the platform.

  • ✗

    Microsoft Sentinel.

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) platform, not a workload within Microsoft Defender XDR. It aggregates data from many sources, including Microsoft Defender services, for correlation, hunting, and response orchestration. Although it integrates with Defender XDR, it operates as a separate higher-level platform rather than being one of the unified security operations components.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.