Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your organization is deploying Microsoft Defender XDR to detect and respond to advanced threats. You need to ensure that security alerts from Microsoft Defender for Endpoint are automatically correlated with alerts from Microsoft Defender for Office 365. What should you configure?

⚠ Common exam trap

Candidates often think additional tools like Sentinel or custom rules are needed for correlation, but Microsoft Defender XDR provides automatic cross-service correlation by default when all services are in the same tenant and incidents are enabled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Ensure that all Microsoft Defender services are onboarded to the same tenant and that the incidents feature is enabled

Microsoft Defender XDR automatically correlates alerts from different Microsoft Defender services (e.g., Defender for Endpoint and Defender for Office 365) when they are onboarded to the same tenant and the incidents feature is enabled. This built-in correlation uses the Microsoft 365 Defender backend to fuse related alerts into a single incident, providing a unified view of the attack chain without additional configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Ensure that all Microsoft Defender services are onboarded to the same tenant and that the incidents feature is enabled

    Why this is correct

    Microsoft Defender XDR's core strength lies in its ability to automatically correlate alerts from various Defender services into unified incidents. This powerful cross-domain correlation engine requires all constituent Defender services (e.g., Defender for Endpoint, Office 365, Identity) to be onboarded within the *same* Azure Active Directory tenant. The incidents feature, which drives this correlation, is enabled by default, ensuring a holistic view of attacks and significantly reducing alert fatigue for security operations teams.

  • Configure a custom detection rule in Microsoft 365 Defender

    Why it's wrong here

    Configuring a custom detection rule in Microsoft 365 Defender is designed to identify specific, often unique, threats or activities within your environment that are not covered by standard detections. These rules leverage advanced hunting queries to generate *new* alerts when their conditions are met, based on raw event data. However, they do not automatically correlate *existing* alerts from different Defender services into a unified incident, which is a function of Defender XDR's built-in correlation engine.

  • Create an advanced hunting query to join alerts from different data sources

    Why it's wrong here

    Advanced hunting is a proactive threat hunting tool that allows security analysts to explore raw data using Kusto Query Language (KQL) to uncover breaches or identify suspicious activities. While an advanced hunting query can certainly *display* and *join* related alerts from various data sources for investigative purposes, it is a manual, query-driven process. It does not provide the automatic, continuous correlation of alerts into a managed incident that Microsoft Defender XDR's incident response capabilities offer.

  • Enable Microsoft Sentinel and configure incident creation rules

    Why it's wrong here

    Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that ingests security data from many sources, including Defender XDR. While Sentinel can certainly create its own incidents based on ingested Defender alerts and custom analytics rules, the question specifically concerns the automatic correlation *within* Microsoft Defender XDR itself. This inherent XDR capability functions independently and does not require the deployment or configuration of an external SIEM like Sentinel for its core incident management.

Go deeper

Related to this question

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.