Courseiva

SC-200 Manage a security operations environment Practice Question

Which THREE of the following are features of Microsoft Defender XDR that help manage a security operations environment?

⚠ Common exam trap

Candidates often confuse 'features of Microsoft Defender XDR' with 'features of Microsoft Sentinel' or other Microsoft security products, leading them to select SIEM integration (Option A) or Threat Analytics (Option B) as operational management features when they are not core to Defender XDR's incident management and response capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated investigation and response

Automated Investigation and Response (AIR) in Microsoft Defender XDR uses AI-driven playbooks to automatically investigate alerts and take remediation actions, such as isolating a compromised device or blocking a malicious file, without requiring manual intervention. This directly supports managing a security operations environment by reducing alert fatigue and accelerating incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Sentinel SIEM integration

    Why it's wrong here

    Sentinel SIEM integration is not a built-in feature of Microsoft Defender XDR itself; rather, it is an external connectivity capability where Defender XDR signals can be streamed or connected to Microsoft Sentinel for enterprise-wide SIEM and SOAR workflows. While Defender XDR does offer API-based integration and data connectors to Sentinel, that relationship is an interoperability option, not a native component of the XDR portal. The XDR platform's core features focus on incident correlation, automated response, and hunting across its own Defender product family, with Sentinel acting as a separate cloud-native SIEM layer that can ingest those telemetry streams.

  • ✗

    Threat analytics

    Why it's wrong here

    Threat analytics is a feature belonging to Microsoft Defender for Endpoint (MDE) and also available in Microsoft Defender for Office 365, not an inherent feature of Defender XDR as a unified platform. It provides curated threat intelligence reports about active adversaries, vulnerabilities, and recommended mitigations, but it operates at the product-specific level rather than representing cross-domain correlation. In contrast, Defender XDR's value proposition is weaving together signals from MDE, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps into a single incident and hunting experience. Confusing product-specific features with platform-level capabilities is a common pitfall when answering this question.

  • ✓

    Automated investigation and response

    Why this is correct

    Automated investigation and response (AIR) is a core feature of Microsoft Defender XDR because it enables the platform to orchestrate playbooks across email, endpoints, identities, and cloud apps following an alert trigger. When a suspicious entity is detected, AIR automatically runs investigations, pauses or blocks malicious activities, and takes remediation actions such as quarantining files or disabling accounts — all while keeping security teams informed via the Action Center. This cross-product automation is what distinguishes XDR from individual Defender products, and it is explicitly listed as a primary capability of Defender XDR. The process uses AI-driven assessments to determine whether a threat is malicious, and it helps contain breaches before human analysts can intervene.

  • ✓

    Advanced hunting

    Why this is correct

    Advanced hunting in Microsoft Defender XDR is a powerful query-based threat hunting tool that allows security teams to search raw telemetry across endpoints, email, identities, and cloud apps from a single interface. It leverages a shared schema (such as IdentityInfo, EmailEvents, and DeviceProcessEvents) so that analysts can write Kusto Query Language (KQL) queries that correlate activities across multiple data sources without needing to pivot between different consoles. This capability is critical for proactive threat hunting, as it enables custom detection rules and historical investigations that go beyond predefined alerting. Advanced hunting is a first-class feature of Defender XDR, not an add-on or separate service, making it one of the correct answers.

  • ✓

    Unified incident management

    Why this is correct

    Unified incident management is a defining feature of Microsoft Defender XDR, as it aggregates alerts and related evidence from Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps into a single incident queue. Instead of viewing isolated alerts in separate consoles, security analysts see a consolidated incident with an attack story, affected assets, and automated response status — which drastically reduces triage time and alert fatigue. The XDR incident queue provides a unified view that includes severity, status, and classification, and all incident actions can be taken from one pane of glass. This cross-product incident correlation is a core reason organizations adopt Defender XDR, so it is clearly a correct feature in this question.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.