SC-900 Practice Question: Describe the concepts of security, compliance, and identity
An organization wants to ensure that its security team can quickly identify and respond to threats across all workloads, including identities, endpoints, email, and cloud apps. Which Microsoft security solution provides a unified incident management experience?
⚠ Common exam trap
SC-900 often tests the distinction between Microsoft Sentinel (SIEM/SOAR) and Microsoft Defender XDR (unified XDR) — candidates confuse 'unified incident management' with Sentinel's incident queue and pick the wrong product.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR
Microsoft Defender XDR is the unified extended detection and response platform that correlates signals across Microsoft 365 Defender workloads — Defender for Identity, Defender for Endpoint, Defender for Office 365, and Defender for Cloud Apps — into a single incident queue and investigation experience in the Microsoft 365 Defender portal. This cross-domain correlation is exactly what 'unified incident management across identities, endpoints, email, and cloud apps' describes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a SIEM/SOAR platform for log ingestion, analytics and automation, not the unified cross-workload incident queue spanning identities, endpoints, email and cloud apps. It is tempting because Sentinel does provide incident management, but only for data routed into its workspace; Microsoft Defender XDR is the correct choice here.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Defender for Cloud protects infrastructure and multi-cloud workloads via posture management and workload protection, not email or identity signals. It is tempting because it aggregates cloud security findings, but it would be correct for securing servers and containers, not for unified incident correlation across all four domains.
- ✓
Microsoft Defender XDR
Why this is correct
Microsoft Defender XDR correlates signals across identities, endpoints, email and cloud apps into unified incidents, giving the security team one portal for detection and response. This satisfies the requirement for a unified incident management experience spanning all workloads.
- ✗
Microsoft Defender for Identity
Why it's wrong here
Defender for Identity monitors on-premises Active Directory signals such as domain controller traffic, covering only identity, not endpoints, email, or cloud apps. It is tempting because it does detect identity threats, but unified cross-workload incident management belongs to Microsoft Defender XDR.
Go deeper
Related to this question
Learn chapter
Defender Vulnerability Management Basics
Key term
Defender for Cloud
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides unified security management and threat protection across hybrid and multi-cloud environments.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.