Key Capabilities of Microsoft Defender XDR
Which TWO of the following are capabilities of Microsoft Defender XDR? (Choose two.)
Quick Answer
The answer is automated investigation and response across domains, which is a core capability of Microsoft Defender XDR. This is correct because XDR, or Extended Detection and Response, is specifically designed to correlate alerts from multiple domains—such as endpoint, email, identity, and cloud apps—into a single incident, enabling cross-domain detection that reveals the full attack story in one place. On the SC-900 exam, this concept tests your understanding of how Microsoft’s security solutions integrate beyond siloed tools; a common trap is confusing XDR with a single-domain tool like Microsoft Defender for Endpoint. Remember that “X” in XDR stands for “cross-domain,” so think of it as the glue that connects alerts across email, identity, endpoints, and cloud apps. A helpful memory tip: “X marks the spot across all domains.”
⚠ Common exam trap
Many exam-takers confuse the broad security portfolio—such as DLP, SIEM, and identity governance—with the specific cross-domain correlation and automated response capabilities that define Microsoft Defender XDR.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Correlate alerts from multiple domains into a single incident
Option A is correct because Microsoft Defender XDR's core capability is incident correlation: it stitches together related alerts from the different Defender workloads (Defender for Endpoint, Identity, Office 365, Cloud Apps) into a single unified incident so analysts see the full attack story rather than isolated alerts. Option E is correct because Defender XDR provides automated investigation and response (AIR) that spans those domains, automatically investigating alerts, remediating threats, and allowing actions to be taken across endpoints, identities, and email. Option B is not a Defender XDR capability; data loss prevention for sensitive information is delivered by Microsoft Purview (e.g., DLP policies in Purview/Defender for Cloud Apps context), not as a Defender XDR function. Option C is not correct because centralized log analytics with custom KQL queries is the role of Microsoft Sentinel (or Log Analytics workspaces), not Defender XDR itself. Option D is not correct because identity governance and access reviews are capabilities of Microsoft Entra ID Governance, not Defender XDR.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Correlate alerts from multiple domains into a single incident
Why this is correct
Microsoft Defender XDR fuses signals from endpoints, identities, email and cloud apps, correlating related alerts into one incident so analysts see the full attack story. This cross-domain correlation is the core capability distinguishing it from standalone Defender workloads.
- ✗
Data loss prevention for sensitive information
Why it's wrong here
Data loss prevention is a Microsoft Purview capability, classifying and blocking sensitive content across services; Defender XDR instead correlates and remediates incidents spanning endpoints, email, identities and cloud apps. It tempts because both concern data protection, but DLP enforces content policy rather than providing cross-domain detection and response.
- ✗
Centralized log analytics for custom queries
Why it's wrong here
Centralised log analytics for custom queries is Microsoft Sentinel's role, built on a Log Analytics workspace with KQL; Defender XDR surfaces correlated incidents and advanced hunting rather than serving as the general-purpose log platform. It tempts because XDR includes hunting queries, but those operate on its own telemetry, not arbitrary ingested logs.
- ✗
Identity governance and access reviews
Why it's wrong here
Identity governance and access reviews sit in Microsoft Entra ID Governance, covering entitlement management and lifecycle decisions, not threat detection across endpoints, email, identities and apps. It tempts because Defender XDR correlates identity signals, yet governance controls permissions rather than detecting and responding to attacks.
- ✓
Automated investigation and response across domains
Why this is correct
Automated investigation and response lets Microsoft Defender XDR investigate alerts across endpoints, identities, email and cloud apps, then remediate threats automatically or on approval. This cross-domain orchestration is a defining capability, reducing manual triage effort across the unified incident queue.
Go deeper
Related to this question
Learn chapter
Attack Surface Reduction Rules
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE capabilities are provided by Microsoft Defender XDR? (Choose THREE.)
medium- A.Cloud security posture management
- ✓ B.Advanced hunting
- ✓ C.Automated investigation and response
- ✓ D.Incident management
- E.Vulnerability management
Why B: Microsoft Defender XDR provides advanced hunting (B), a Kusto Query Language (KQL)-based tool that lets security teams proactively search across up to 30 days of raw endpoint, email, identity, and cloud app telemetry to hunt for threats. It also delivers automated investigation and response (C), using automated investigation playbooks and self-healing actions to triage and remediate alerts across the Defender workloads. Incident management (D) is a core capability, correlating related alerts from multiple Defender products into a single incident with a unified timeline and remediation workflow in the Microsoft 365 Defender portal. Cloud security posture management (A) is a Microsoft Defender for Cloud capability, not Defender XDR, and vulnerability management (E) is provided by Microsoft Defender Vulnerability Management (or Defender for Endpoint), so neither belongs to the Defender XDR feature set.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.