SC-900 - Microsoft Security Solutions (38% of the exam) - Section 3.4

Describe threat protection with Microsoft Defender XDR.

Describe how Microsoft Defender XDR unifies signals from Defender for Office 365, Defender for Endpoint, Defender for Cloud Apps, and Defender for Identity into a single extended detection and response platform. Recognise the Microsoft Defender portal as the centralised console where analysts investigate incidents and coordinate remediation across these workloads.

Defender XDRDefender for Office 365Defender for EndpointDefender for Cloud AppsDefender for IdentityMicrosoft Defender portal

Practice question for this objective

Free sampleMicrosoft Security Solutionsmedium

A CISO is explaining how Microsoft Defender XDR unifies its component workloads into a coordinated suite. Which TWO statements about Defender XDR are correct? Select TWO.

  • AIt is principally a cloud security posture management tool for scoring resource configurations.
  • BIt correlates signals across endpoints, identities, email, and apps into unified incidents. Correct
  • CIt is a SIEM whose main role is long-term retention and KQL querying of ingested logs.
  • DThe Microsoft Defender portal is the central console for managing detections and response. Correct
  • EIts primary function is brokering RDP and SSH connectivity to virtual machines securely.
Defender XDR unifies signals across endpoints, identities, email and apps into correlated incidents, managed from the Microsoft Defender portal as its central console. Defender XDR correlates its workloads' signals into unified incidents and is operated from the Microsoft Defender portal. It is not a posture tool, not a SIEM, and not a connectivity broker, so those distractors describe Defender for Cloud, Sentinel and Bastion instead.

Why A is wrong: Posture scoring of configurations is Defender for Cloud; Defender XDR is cross-workload detection and response.

Why B is correct: Defender XDR stitches alerts from its workloads into single incidents revealing the full attack story.

Why C is wrong: Long-term log retention and querying is Microsoft Sentinel, the SIEM, not the Defender XDR detection suite.

Why D is correct: The Microsoft Defender portal is the single pane of glass uniting the XDR workloads for investigation and response.

Why E is wrong: Brokered RDP and SSH connectivity is Azure Bastion, wholly unrelated to the Defender XDR threat suite.

See more SC-900 practice questions, answers explained.

Exam traps in Microsoft Security Solutions

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-900 bank for this domain.

  • It opens a manual ticket and waits for an analyst to clear the file from mailboxes by hand.

    Why it is wrong: The grounding describes automatic real-time sharing between products, not a manual ticket; relying on hand clearance contradicts the suite's automated response design.

  • Microsoft Defender for Identity

    Why it is wrong: Defender for Identity monitors on-premises identity signals and is not the endpoint detection and response capability included with Defender for Servers.

  • Defender for Identity detonates email attachments and inspects URLs at time of click.

    Why it is wrong: Attachment detonation and safe links are Defender for Office 365 features, not Defender for Identity capabilities.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.