What Are the Core Features of Microsoft Defender XDR?
Which TWO features are part of Microsoft Defender XDR?
Quick Answer
The correct answer is incident management across workloads and automated investigation and response, as these two features are core components of Microsoft Defender XDR. Microsoft Defender XDR is designed as a unified, pre- and post-breach enterprise defense suite that correlates signals across endpoints, email, identities, and cloud apps to provide a single incident queue and automated remediation actions. On the SC-900 exam, this question tests your ability to distinguish the native XDR capabilities from adjacent Microsoft security solutions—a common trap is confusing Defender for Cloud Apps or Entra ID Protection as part of XDR when they are separate products that integrate with it. A helpful memory tip is to think of XDR as the "incident hub" that manages and responds across workloads, while other tools like cloud app security or identity protection are specialized modules feeding into that hub.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated investigation and response
Automated investigation and response (AIR) is a core capability of Microsoft Defender XDR, enabling automatic response to threats across workloads. Option E is correct because Incident management across workloads allows security teams to manage and correlate incidents from multiple sources in a unified console within Defender XDR. Option B is incorrect because Cloud app discovery is a feature of Microsoft Defender for Cloud Apps, not Defender XDR. Option C is incorrect because Endpoint data loss prevention (Endpoint DLP) is part of Microsoft Purview compliance solutions. Option D is incorrect because Identity Protection is a feature of Microsoft Entra ID (formerly Azure AD), not Defender XDR.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automated investigation and response
Why this is correct
XDR includes AIR capabilities.
- ✗
Cloud app discovery
Why it's wrong here
Cloud app discovery is part of Defender for Cloud Apps.
- ✗
Endpoint data loss prevention
Why it's wrong here
Endpoint DLP is part of Microsoft Purview.
- ✗
Identity Protection
Why it's wrong here
Identity Protection is part of Entra ID Protection.
- ✓
Incident management across workloads
Why this is correct
XDR provides unified incident management.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security team uses Microsoft Defender XDR to respond to incidents. Which THREE components are part of Microsoft Defender XDR?
medium- ✓ A.Microsoft Defender for Office 365
- ✓ B.Microsoft Defender for Endpoint
- C.Microsoft Sentinel
- D.Microsoft Intune
- ✓ E.Microsoft Defender for Identity
Why A: Microsoft Defender XDR is a unified extended detection and response platform that natively integrates signals from Microsoft Defender for Office 365 (email and collaboration protection), Microsoft Defender for Endpoint (endpoint detection and response), and Microsoft Defender for Identity (on-premises identity threat detection). These three components share telemetry and automate incident correlation across domains, which is the core purpose of Defender XDR.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.