SC-200 Manage a security operations environment Practice Question
Which TWO Microsoft 365 security solutions include capabilities for managing security incidents?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR
Microsoft Defender XDR (B) is correct because it natively correlates alerts across endpoints, identities, email, and cloud apps into unified incidents, providing incident management through the Microsoft Defender portal with investigation, automated response, and remediation capabilities. Microsoft Sentinel (E) is correct because it is a cloud-native SIEM/SOAR solution that creates incidents from analytics rules and offers full incident management, including triage, investigation graphs, automation rules, and playbooks. Microsoft Intune (A) is a device and application management (MDM/MAM) service and does not provide security incident management. Microsoft Entra ID Protection (C) detects identity-based risks and generates risk detections and risky user/sign-in reports, but it is not an incident management solution. Microsoft Purview (D) focuses on data governance, compliance, and information protection (e.g., DLP, eDiscovery), not on managing security incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Intune
Why it's wrong here
Microsoft Intune manages device configuration, compliance and app deployment, not security incident management. It is tempting because Intune reports device compliance signals, but incident correlation, investigation and response are provided by Microsoft Defender XDR and Microsoft Sentinel.
- ✓
Microsoft Defender XDR
Why this is correct
Microsoft Defender XDR includes a unified incident queue and automated investigation and response, letting security teams manage and remediate incidents across endpoints, identities, email and cloud apps. This built-in incident management capability satisfies the requirement for a Microsoft 365 security solution that manages security incidents.
- ✗
Microsoft Entra ID Protection
Why it's wrong here
Microsoft Entra ID Protection detects and reports risky users and sign-ins, but does not manage security incidents. It is tempting because it generates risk alerts, yet incident triage, investigation and response are handled by Microsoft Defender XDR and Microsoft Sentinel.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview handles data governance, compliance and information protection, not incident management. It is tempting because Purview surfaces alerts and audit data, but incident triage, investigation and response belong to Microsoft Defender XDR and Microsoft Sentinel.
- ✓
Microsoft Sentinel
Why this is correct
Microsoft Sentinel provides full incident management through its incident queue, where alerts are correlated into incidents that can be assigned, investigated and closed. This satisfies the stem's requirement for managing security incidents, unlike solutions offering only alerting or posture assessment without a dedicated incident lifecycle.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.