Courseiva

What Are the Core Features of Microsoft Defender XDR?

Which TWO features are part of Microsoft Defender XDR?

Quick Answer

The correct answer is incident management across workloads and automated investigation and response, as these two features are core components of Microsoft Defender XDR. Microsoft Defender XDR is designed as a unified, pre- and post-breach enterprise defense suite that correlates signals across endpoints, email, identities, and cloud apps to provide a single incident queue and automated remediation actions. On the SC-900 exam, this question tests your ability to distinguish the native XDR capabilities from adjacent Microsoft security solutions—a common trap is confusing Defender for Cloud Apps or Entra ID Protection as part of XDR when they are separate products that integrate with it. A helpful memory tip is to think of XDR as the "incident hub" that manages and responds across workloads, while other tools like cloud app security or identity protection are specialized modules feeding into that hub.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated investigation and response

Option A is correct because Automated investigation and response (AIR) is a core Microsoft Defender XDR capability that automatically investigates alerts, correlates evidence across endpoints, identities, email, and cloud apps, and applies remediation actions. Option E is correct because incident management across workloads is the defining feature of Defender XDR, which correlates alerts from Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps into unified incidents in the Microsoft 365 Defender portal. Option B is incorrect because Cloud app discovery is a Microsoft Defender for Cloud Apps (formerly MCAS) capability, not a Defender XDR feature itself. Option C is incorrect because Endpoint data loss prevention is a Microsoft Purview capability, not part of Defender XDR. Option D is incorrect because Identity Protection is a Microsoft Entra ID feature, distinct from Defender for Identity which is the Defender XDR identity workload.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Automated investigation and response

    Why this is correct

    Automated investigation and response is a core Defender XDR capability, letting the platform triage alerts and execute remediation actions across endpoints, identities and email automatically. This satisfies the stem's requirement for a genuine cross-workload XDR feature rather than a single-product tool.

  • ✗

    Cloud app discovery

    Why it's wrong here

    Cloud app discovery belongs to Microsoft Defender for Cloud Apps, which is a Defender XDR component, yet the question asks which features are part of Defender XDR itself. Discovery is the correct answer when the requirement is shadow-IT visibility rather than naming XDR's constituent workloads.

  • ✗

    Endpoint data loss prevention

    Why it's wrong here

    Endpoint data loss prevention is delivered through Microsoft Purview and Defender for Endpoint integration, not as a standalone Defender XDR feature. It is tempting because Defender XDR surfaces DLP alerts, but the correct answers name the core workloads: Endpoint, Office 365, Identity, and Cloud Apps.

  • ✗

    Identity Protection

    Why it's wrong here

    Microsoft Entra ID Protection is a separate product within Microsoft Entra, not a Microsoft Defender XDR component. It is tempting because Defender XDR correlates identity signals, but its own workloads are Defender for Endpoint, Office 365, Identity, Cloud Apps, and Vulnerability Management.

  • ✓

    Incident management across workloads

    Why this is correct

    Incident management across workloads is central to Defender XDR: it correlates alerts from Defender for Endpoint, Identity, Office 365 and Cloud Apps into one incident queue. This directly satisfies the stem's requirement for a feature spanning multiple Microsoft security workloads.

Go deeper

Related to this question

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security team uses Microsoft Defender XDR to respond to incidents. Which THREE components are part of Microsoft Defender XDR?

medium
  • ✓ A.Microsoft Defender for Office 365
  • ✓ B.Microsoft Defender for Endpoint
  • C.Microsoft Sentinel
  • D.Microsoft Intune
  • ✓ E.Microsoft Defender for Identity

Why A: Microsoft Defender XDR is a unified extended detection and response platform that natively integrates signals from Microsoft Defender for Office 365 (email and collaboration protection), Microsoft Defender for Endpoint (endpoint detection and response), and Microsoft Defender for Identity (on-premises identity threat detection). These three components share telemetry and automate incident correlation across domains, which is the core purpose of Defender XDR.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.