SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization is deploying Microsoft Defender XDR to detect and respond to advanced threats. You need to ensure that security alerts from Microsoft Defender for Endpoint are automatically correlated with alerts from Microsoft Defender for Office 365. What should you configure?
⚠ Common exam trap
Candidates often think additional tools like Sentinel or custom rules are needed for correlation, but Microsoft Defender XDR provides automatic cross-service correlation by default when all services are in the same tenant and incidents are enabled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure that all Microsoft Defender services are onboarded to the same tenant and that the incidents feature is enabled
Microsoft Defender XDR automatically correlates alerts from different Microsoft Defender services (e.g., Defender for Endpoint and Defender for Office 365) when they are onboarded to the same tenant and the incidents feature is enabled. This built-in correlation uses the Microsoft 365 Defender backend to fuse related alerts into a single incident, providing a unified view of the attack chain without additional configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ensure that all Microsoft Defender services are onboarded to the same tenant and that the incidents feature is enabled
Why this is correct
Microsoft Defender XDR's core strength lies in its ability to automatically correlate alerts from various Defender services into unified incidents. This powerful cross-domain correlation engine requires all constituent Defender services (e.g., Defender for Endpoint, Office 365, Identity) to be onboarded within the *same* Azure Active Directory tenant. The incidents feature, which drives this correlation, is enabled by default, ensuring a holistic view of attacks and significantly reducing alert fatigue for security operations teams.
- ✗
Configure a custom detection rule in Microsoft 365 Defender
Why it's wrong here
Configuring a custom detection rule in Microsoft 365 Defender is designed to identify specific, often unique, threats or activities within your environment that are not covered by standard detections. These rules leverage advanced hunting queries to generate *new* alerts when their conditions are met, based on raw event data. However, they do not automatically correlate *existing* alerts from different Defender services into a unified incident, which is a function of Defender XDR's built-in correlation engine.
- ✗
Create an advanced hunting query to join alerts from different data sources
Why it's wrong here
Advanced hunting is a proactive threat hunting tool that allows security analysts to explore raw data using Kusto Query Language (KQL) to uncover breaches or identify suspicious activities. While an advanced hunting query can certainly *display* and *join* related alerts from various data sources for investigative purposes, it is a manual, query-driven process. It does not provide the automatic, continuous correlation of alerts into a managed incident that Microsoft Defender XDR's incident response capabilities offer.
- ✗
Enable Microsoft Sentinel and configure incident creation rules
Why it's wrong here
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that ingests security data from many sources, including Defender XDR. While Sentinel can certainly create its own incidents based on ingested Defender alerts and custom analytics rules, the question specifically concerns the automatic correlation *within* Microsoft Defender XDR itself. This inherent XDR capability functions independently and does not require the deployment or configuration of an external SIEM like Sentinel for its core incident management.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.