A CISO is explaining how Microsoft Defender XDR unifies its component workloads into a coordinated suite. Which TWO statements about Defender XDR are correct? Select TWO.
- AIt is principally a cloud security posture management tool for scoring resource configurations.
- BIt correlates signals across endpoints, identities, email, and apps into unified incidents. Correct
- CIt is a SIEM whose main role is long-term retention and KQL querying of ingested logs.
- DThe Microsoft Defender portal is the central console for managing detections and response. Correct
- EIts primary function is brokering RDP and SSH connectivity to virtual machines securely.
Why A is wrong: Posture scoring of configurations is Defender for Cloud; Defender XDR is cross-workload detection and response.
Why B is correct: Defender XDR stitches alerts from its workloads into single incidents revealing the full attack story.
Why C is wrong: Long-term log retention and querying is Microsoft Sentinel, the SIEM, not the Defender XDR detection suite.
Why D is correct: The Microsoft Defender portal is the single pane of glass uniting the XDR workloads for investigation and response.
Why E is wrong: Brokered RDP and SSH connectivity is Azure Bastion, wholly unrelated to the Defender XDR threat suite.