What Are the Core Features of Microsoft Defender XDR?
Which TWO features are part of Microsoft Defender XDR?
Quick Answer
The correct answer is incident management across workloads and automated investigation and response, as these two features are core components of Microsoft Defender XDR. Microsoft Defender XDR is designed as a unified, pre- and post-breach enterprise defense suite that correlates signals across endpoints, email, identities, and cloud apps to provide a single incident queue and automated remediation actions. On the SC-900 exam, this question tests your ability to distinguish the native XDR capabilities from adjacent Microsoft security solutions—a common trap is confusing Defender for Cloud Apps or Entra ID Protection as part of XDR when they are separate products that integrate with it. A helpful memory tip is to think of XDR as the "incident hub" that manages and responds across workloads, while other tools like cloud app security or identity protection are specialized modules feeding into that hub.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated investigation and response
Option A is correct because Automated investigation and response (AIR) is a core Microsoft Defender XDR capability that automatically investigates alerts, correlates evidence across endpoints, identities, email, and cloud apps, and applies remediation actions. Option E is correct because incident management across workloads is the defining feature of Defender XDR, which correlates alerts from Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps into unified incidents in the Microsoft 365 Defender portal. Option B is incorrect because Cloud app discovery is a Microsoft Defender for Cloud Apps (formerly MCAS) capability, not a Defender XDR feature itself. Option C is incorrect because Endpoint data loss prevention is a Microsoft Purview capability, not part of Defender XDR. Option D is incorrect because Identity Protection is a Microsoft Entra ID feature, distinct from Defender for Identity which is the Defender XDR identity workload.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automated investigation and response
Why this is correct
Automated investigation and response is a core Defender XDR capability, letting the platform triage alerts and execute remediation actions across endpoints, identities and email automatically. This satisfies the stem's requirement for a genuine cross-workload XDR feature rather than a single-product tool.
- ✗
Cloud app discovery
Why it's wrong here
Cloud app discovery belongs to Microsoft Defender for Cloud Apps, which is a Defender XDR component, yet the question asks which features are part of Defender XDR itself. Discovery is the correct answer when the requirement is shadow-IT visibility rather than naming XDR's constituent workloads.
- ✗
Endpoint data loss prevention
Why it's wrong here
Endpoint data loss prevention is delivered through Microsoft Purview and Defender for Endpoint integration, not as a standalone Defender XDR feature. It is tempting because Defender XDR surfaces DLP alerts, but the correct answers name the core workloads: Endpoint, Office 365, Identity, and Cloud Apps.
- ✗
Identity Protection
Why it's wrong here
Microsoft Entra ID Protection is a separate product within Microsoft Entra, not a Microsoft Defender XDR component. It is tempting because Defender XDR correlates identity signals, but its own workloads are Defender for Endpoint, Office 365, Identity, Cloud Apps, and Vulnerability Management.
- ✓
Incident management across workloads
Why this is correct
Incident management across workloads is central to Defender XDR: it correlates alerts from Defender for Endpoint, Identity, Office 365 and Cloud Apps into one incident queue. This directly satisfies the stem's requirement for a feature spanning multiple Microsoft security workloads.
Go deeper
Related to this question
Learn chapter
Microsoft Entra Password Protection
Key term
Defender for Cloud
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides unified security management and threat protection across hybrid and multi-cloud environments.
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security team uses Microsoft Defender XDR to respond to incidents. Which THREE components are part of Microsoft Defender XDR?
medium- ✓ A.Microsoft Defender for Office 365
- ✓ B.Microsoft Defender for Endpoint
- C.Microsoft Sentinel
- D.Microsoft Intune
- ✓ E.Microsoft Defender for Identity
Why A: Microsoft Defender XDR is a unified extended detection and response platform that natively integrates signals from Microsoft Defender for Office 365 (email and collaboration protection), Microsoft Defender for Endpoint (endpoint detection and response), and Microsoft Defender for Identity (on-premises identity threat detection). These three components share telemetry and automate incident correlation across domains, which is the core purpose of Defender XDR.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.