SC-100 - Design Security Operations, Identity, and Compliance Capabilities (27% of the exam) - Section 2.1

Design solutions for security operations, including detection, response, logging, SOAR, and threat detection coverage.

Design a security operations architecture that integrates Microsoft Defender XDR for extended detection and response (XDR) with Microsoft Sentinel as the SIEM and SOAR platform, mapped to MITRE ATT&CK matrices. Choose the appropriate combination of Microsoft Purview Audit, threat hunting, and incident response capabilities to achieve the required detection and coverage depth.

Microsoft Defender XDRMicrosoft SentinelSIEM and SOARextended detection and response (XDR)MITRE ATT&CK matricesMicrosoft Purview Auditthreat hunting and incident response

Practice question for this objective

Free sampleDesign Security Operations, Identity, and Compliance Capabilitieshard

An enterprise runs both Microsoft Sentinel for its multicloud and third-party data and Microsoft Defender XDR for its Microsoft workload alerts, and its analysts switch between two consoles and reconcile two separate incident queues for what is often the same intrusion. Leadership wants a design where the team works a single correlated incident queue and one hunting surface that spans both the SIEM data and the XDR detections, without losing the multicloud and third-party ingestion Sentinel already provides. Which design decision best satisfies this consolidation requirement?

  • ABuild a Microsoft Sentinel workbook that pulls incidents from both the Sentinel tables and the Defender XDR tables so analysts can monitor a single dashboard view of all incidents across the two products during each shift.
  • BRetire Microsoft Sentinel and rely solely on Microsoft Defender XDR, re-creating the multicloud and third-party log analytics as advanced hunting queries inside the Defender portal so everything lives in one place.
  • CDeploy the Microsoft Defender for Cloud connector so the cloud-workload alerts stream into Microsoft Sentinel as incidents, giving the analysts one queue in the Sentinel portal for the workload detections alongside their other sources.
  • DOnboard Microsoft Sentinel into the Microsoft Defender portal as the unified security operations platform so Sentinel and Defender XDR share one correlated incident queue and one advanced hunting surface while Sentinel keeps ingesting multicloud and third-party data. Correct
Onboarding Microsoft Sentinel into the Microsoft Defender portal unifies SIEM and XDR into one correlated incident queue and one hunting surface while retaining multicloud ingestion. The unified security operations platform connects Microsoft Sentinel to the Microsoft Defender portal so that SIEM incidents and Defender XDR incidents are correlated and presented in a single queue with one advanced hunting experience, removing the need to reconcile two consoles while Sentinel retains its multicloud and third-party data ingestion.

Why A is wrong: A workbook can visualise incidents from both sources on one dashboard, but it is a read-only monitoring tile and does not merge the two incident queues into one investigable, actionable surface, so analysts still triage and respond in two separate consoles.

Why B is wrong: Consolidating into one portal is the goal, but removing Sentinel discards the SIEM's broad multicloud and third-party ingestion that the requirement explicitly insists on keeping, so this design loses essential coverage to achieve the single surface.

Why C is wrong: The Defender for Cloud connector brings cloud-workload alerts into Sentinel, but it addresses only one alert source and leaves the broader Defender XDR endpoint and identity incidents in their own portal, so the dual-console and dual-queue problem remains.

Why D is correct: Onboarding Sentinel into the Defender portal delivers Microsoft's unified security operations platform, presenting a single correlated incident queue and one advanced hunting experience across SIEM and XDR data while Sentinel continues to ingest the multicloud and third-party sources, which satisfies every part of the requirement.

See more SC-100 practice questions, answers explained.

Exam traps in Design Security Operations, Identity, and Compliance Capabilities

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-100 bank for this domain.

  • Microsoft Defender XDR, because its unified incident queue stitches together related alerts from across the Microsoft Defender workloads into a single investigation experience.

    Why it is wrong: Defender XDR is tempting because it does correlate alerts into unified incidents, but it covers Microsoft first-party telemetry and cannot natively ingest arbitrary firewall, third-party, or multicloud log sources or run broad orchestration playbooks, so it cannot be the central plane here.

  • Disable the Defender XDR incident engine and rebuild equivalent correlation logic as Microsoft Sentinel analytics rules so that all investigation happens only inside the SIEM.

    Why it is wrong: Rebuilding the correlation in Sentinel is tempting because it centralises everything, but it discards the native cross-workload incident logic of Defender XDR and forces analysts to recreate detections that Microsoft already maintains, so it adds cost and reduces fidelity.

  • Increase the Microsoft Defender for Endpoint automated investigation and response automation level to full so confirmed endpoint threats are remediated on each device without analyst approval and the response queue stays clear.

    Why it is wrong: Raising endpoint automation speeds remediation of detections that already fire, which is tempting for an overloaded team, but it neither maps detections to an adversary taxonomy nor exposes where coverage is missing, so it does not address the detection-coverage measurement the requirement specifies.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.