SC-900 Microsoft Defender XDR Practice Question
Which THREE components are part of Microsoft Defender XDR? (Choose three.)
⚠ Common exam trap
Test-takers frequently confuse Microsoft Sentinel (a SIEM) as part of Defender XDR, but Sentinel is an external analytics layer that can ingest Defender XDR data, not a built-in component of the XDR suite.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Office 365
Microsoft Defender XDR is Microsoft's extended detection and response suite that unifies several Defender workloads under a single portal. Option B, Microsoft Defender for Office 365, is correct because it is one of the core Defender XDR pillars, providing protection for email, collaboration tools, and phishing/URL detonation signals. Option D, Microsoft Defender for Identity, is correct because it monitors on-premises Active Directory and identity signals (via domain controller sensors) and feeds those detections into Defender XDR. Option E, Microsoft Defender for Endpoint, is correct because it is the endpoint pillar of Defender XDR, delivering device-level detection, investigation, and response. Option A, Microsoft Purview, is not part of Defender XDR; it is a separate compliance and data-governance suite. Option C, Microsoft Sentinel, is also not a Defender XDR component; it is a standalone cloud-native SIEM/SOAR solution that can integrate with Defender XDR but is not one of its constituent workloads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview is a data governance, compliance and information-protection suite, not a Defender XDR workload. It is tempting because it surfaces insider-risk and data-loss signals that complement threat detection, but that applies to compliance and data security programmes, not to the XDR component list.
- ✓
Microsoft Defender for Office 365
Why this is correct
Defender for Office 365 contributes email, collaboration and phishing protection signals into the unified incident queue, so it is one of the three XDR pillars alongside Defender for Endpoint and Defender for Identity. Its alerts feed the correlated incidents the stem requires.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM and SOAR product that ingests logs across many sources, and it sits outside the Defender XDR component set. It is tempting because it correlates security signals and integrates with Defender, but that applies to standalone SIEM scenarios, not to the bundled XDR components.
- ✓
Microsoft Defender for Identity
Why this is correct
Defender for Identity monitors on-premises Active Directory domain controller traffic, surfacing compromised-identity and lateral-movement signals into the unified incident queue. It is one of the three XDR pillars, satisfying the stem's requirement for correlated cross-domain incidents.
- ✓
Microsoft Defender for Endpoint
Why this is correct
Defender for Endpoint supplies device-level detection and response signals, feeding endpoint alerts into the unified incident queue. It is one of the three XDR pillars, so it satisfies the stem's requirement for correlated incidents across email, identity and endpoint domains.
Go deeper
Related to this question
Learn chapter
Microsoft Defender for Identity
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.