SC-900 - Microsoft Security Solutions - Section 3.4

Describe threat protection with Microsoft Defender XDR.

Describe how Microsoft Defender XDR unifies signals from Defender for Office 365, Defender for Endpoint, Defender for Cloud Apps, and Defender for Identity into a single extended detection and response platform. Recognise the Microsoft Defender portal as the centralised console where analysts investigate incidents and coordinate remediation across these workloads.

Defender XDRDefender for Office 365Defender for EndpointDefender for Cloud AppsDefender for IdentityMicrosoft Defender portal

Practice question for this objective

Free sampleMicrosoft Security Solutionsmedium

A CISO is explaining how Microsoft Defender XDR unifies its component workloads into a coordinated suite. Which TWO statements about Defender XDR are correct? Select TWO.

  • AIt is principally a cloud security posture management tool for scoring resource configurations.
  • BIt correlates signals across endpoints, identities, email, and apps into unified incidents. Correct
  • CIt is a SIEM whose main role is long-term retention and KQL querying of ingested logs.
  • DThe Microsoft Defender portal is the central console for managing detections and response. Correct
  • EIts primary function is brokering RDP and SSH connectivity to virtual machines securely.
Defender XDR unifies signals across endpoints, identities, email and apps into correlated incidents, managed from the Microsoft Defender portal as its central console. Defender XDR correlates its workloads' signals into unified incidents and is operated from the Microsoft Defender portal. It is not a posture tool, not a SIEM, and not a connectivity broker, so those distractors describe Defender for Cloud, Sentinel and Bastion instead.

Why A is wrong: Posture scoring of configurations is Defender for Cloud; Defender XDR is cross-workload detection and response.

Why B is correct: Defender XDR stitches alerts from its workloads into single incidents revealing the full attack story.

Why C is wrong: Long-term log retention and querying is Microsoft Sentinel, the SIEM, not the Defender XDR detection suite.

Why D is correct: The Microsoft Defender portal is the single pane of glass uniting the XDR workloads for investigation and response.

Why E is wrong: Brokered RDP and SSH connectivity is Azure Bastion, wholly unrelated to the Defender XDR threat suite.

See more SC-900 practice questions, answers explained.

More in this domain

Back to all Microsoft Security Solutions objectives, or the SC-900 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.