Courseiva

What Are the Core Features of Microsoft Defender XDR?

Which TWO features are part of Microsoft Defender XDR?

Quick Answer

The correct answer is incident management across workloads and automated investigation and response, as these two features are core components of Microsoft Defender XDR. Microsoft Defender XDR is designed as a unified, pre- and post-breach enterprise defense suite that correlates signals across endpoints, email, identities, and cloud apps to provide a single incident queue and automated remediation actions. On the SC-900 exam, this question tests your ability to distinguish the native XDR capabilities from adjacent Microsoft security solutions—a common trap is confusing Defender for Cloud Apps or Entra ID Protection as part of XDR when they are separate products that integrate with it. A helpful memory tip is to think of XDR as the "incident hub" that manages and responds across workloads, while other tools like cloud app security or identity protection are specialized modules feeding into that hub.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Automated investigation and response

Automated investigation and response (AIR) is a core capability of Microsoft Defender XDR, enabling automatic response to threats across workloads. Option E is correct because Incident management across workloads allows security teams to manage and correlate incidents from multiple sources in a unified console within Defender XDR. Option B is incorrect because Cloud app discovery is a feature of Microsoft Defender for Cloud Apps, not Defender XDR. Option C is incorrect because Endpoint data loss prevention (Endpoint DLP) is part of Microsoft Purview compliance solutions. Option D is incorrect because Identity Protection is a feature of Microsoft Entra ID (formerly Azure AD), not Defender XDR.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Automated investigation and response

    Why this is correct

    XDR includes AIR capabilities.

  • Cloud app discovery

    Why it's wrong here

    Cloud app discovery is part of Defender for Cloud Apps.

  • Endpoint data loss prevention

    Why it's wrong here

    Endpoint DLP is part of Microsoft Purview.

  • Identity Protection

    Why it's wrong here

    Identity Protection is part of Entra ID Protection.

  • Incident management across workloads

    Why this is correct

    XDR provides unified incident management.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security team uses Microsoft Defender XDR to respond to incidents. Which THREE components are part of Microsoft Defender XDR?

medium
  • A.Microsoft Defender for Office 365
  • B.Microsoft Defender for Endpoint
  • C.Microsoft Sentinel
  • D.Microsoft Intune
  • E.Microsoft Defender for Identity

Why A: Microsoft Defender XDR is a unified extended detection and response platform that natively integrates signals from Microsoft Defender for Office 365 (email and collaboration protection), Microsoft Defender for Endpoint (endpoint detection and response), and Microsoft Defender for Identity (on-premises identity threat detection). These three components share telemetry and automate incident correlation across domains, which is the core purpose of Defender XDR.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.