Which signal sources can Microsoft Defender XDR correlate into a single incident in the Microsoft Defender portal? (Select 3 answers)
- AEndpoint detection alerts generated by Microsoft Defender for Endpoint Correct
- BIdentity attack alerts generated by Microsoft Defender for Identity Correct
- CCloud app activity alerts from Microsoft Defender for Cloud Apps Correct
- DDevice compliance state changes reported by Microsoft Intune
- EMicrosoft Purview eDiscovery (Standard) case lifecycle events
Why A is correct: Correct. Endpoint detection alerts generated by Microsoft Defender for Endpoint is one of the keyed answers. Defender XDR correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Office 365, Microsoft Entra ID Protection, and Microsoft Defender for Cloud into combined incidents in the Microsoft Defender portal.
Why B is correct: Correct. Identity attack alerts generated by Microsoft Defender for Identity is one of the keyed answers. Defender XDR correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Office 365, Microsoft Entra ID Protection, and Microsoft Defender for Cloud into combined incidents in the Microsoft Defender portal.
Why C is correct: Correct. Cloud app activity alerts from Microsoft Defender for Cloud Apps is one of the keyed answers. Defender XDR correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Office 365, Microsoft Entra ID Protection, and Microsoft Defender for Cloud into combined incidents in the Microsoft Defender portal.
Why D is wrong: Intune device compliance state changes feed Conditional Access and reporting, not Defender XDR incident correlation. Intune is a management plane, not a Defender signal source.
Why E is wrong: Purview eDiscovery (Standard) is a legal and investigation workload for content search and case management; its case events do not feed XDR incidents.