Courseiva

SC-900 Microsoft Defender XDR Practice Question

Which THREE components are part of Microsoft Defender XDR? (Choose three.)

⚠ Common exam trap

Test-takers frequently confuse Microsoft Sentinel (a SIEM) as part of Defender XDR, but Sentinel is an external analytics layer that can ingest Defender XDR data, not a built-in component of the XDR suite.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Office 365

Microsoft Defender XDR is Microsoft's extended detection and response suite that unifies several Defender workloads under a single portal. Option B, Microsoft Defender for Office 365, is correct because it is one of the core Defender XDR pillars, providing protection for email, collaboration tools, and phishing/URL detonation signals. Option D, Microsoft Defender for Identity, is correct because it monitors on-premises Active Directory and identity signals (via domain controller sensors) and feeds those detections into Defender XDR. Option E, Microsoft Defender for Endpoint, is correct because it is the endpoint pillar of Defender XDR, delivering device-level detection, investigation, and response. Option A, Microsoft Purview, is not part of Defender XDR; it is a separate compliance and data-governance suite. Option C, Microsoft Sentinel, is also not a Defender XDR component; it is a standalone cloud-native SIEM/SOAR solution that can integrate with Defender XDR but is not one of its constituent workloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Purview

    Why it's wrong here

    Microsoft Purview is a data governance, compliance and information-protection suite, not a Defender XDR workload. It is tempting because it surfaces insider-risk and data-loss signals that complement threat detection, but that applies to compliance and data security programmes, not to the XDR component list.

  • ✓

    Microsoft Defender for Office 365

    Why this is correct

    Defender for Office 365 contributes email, collaboration and phishing protection signals into the unified incident queue, so it is one of the three XDR pillars alongside Defender for Endpoint and Defender for Identity. Its alerts feed the correlated incidents the stem requires.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM and SOAR product that ingests logs across many sources, and it sits outside the Defender XDR component set. It is tempting because it correlates security signals and integrates with Defender, but that applies to standalone SIEM scenarios, not to the bundled XDR components.

  • ✓

    Microsoft Defender for Identity

    Why this is correct

    Defender for Identity monitors on-premises Active Directory domain controller traffic, surfacing compromised-identity and lateral-movement signals into the unified incident queue. It is one of the three XDR pillars, satisfying the stem's requirement for correlated cross-domain incidents.

  • ✓

    Microsoft Defender for Endpoint

    Why this is correct

    Defender for Endpoint supplies device-level detection and response signals, feeding endpoint alerts into the unified incident queue. It is one of the three XDR pillars, so it satisfies the stem's requirement for correlated incidents across email, identity and endpoint domains.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.