certslothcertsloth
SC-900/Topic 04

Microsoft / Foundational

Defender XDR, Sentinel and Threat Operations

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: XDR connects product signals; SIEM connects the wider evidence.

Must remember

Defender XDR correlates supported security signals into incidents. Defender for Endpoint addresses endpoint protection/detection; Defender for Office 365 covers supported email/collaboration threats; Defender for Identity analyzes supported identity infrastructure; Defender for Cloud Apps addresses SaaS/cloud-app visibility and controls. Vulnerability Management prioritizes weaknesses; threat intelligence supplies adversary/indicator context.

Microsoft Sentinel is a SIEM/SOAR platform: collect and correlate telemetry, detect suspicious patterns, investigate incidents and orchestrate response. Data connectors ingest evidence; analytics rules detect conditions; automation/playbooks support response. A connector alone does not mean every required detection is enabled or tuned.

The Defender portal brings supported investigation experiences together. An alert is a signal; an incident groups related evidence and response work. Analysts validate, scope, contain and investigate rather than treating every alert as proven malicious activity. Automated response needs suitable permissions and safeguards.

SIEM emphasizes centralized event analysis; SOAR emphasizes orchestration/automation; XDR emphasizes correlated detection/response across integrated security products. The categories overlap in modern platforms, but the exam still asks which capability solves a stated need.

Choose under exam pressure

Requirement Choice and reason
Correlate supported endpoint/email/identity attacks Defender XDR.
Ingest broad cross-platform logs and automate response Sentinel SIEM/SOAR.
Find risky SaaS use Defender for Cloud Apps.

Traps

  • Defender for Cloud and Defender for Cloud Apps are different products.
  • An alert count does not directly measure confirmed incidents.

Active recall

1. What does XDR correlate?

Signals across integrated detection/response products.

2. SIEM versus SOAR?

Security event analysis versus response orchestration/automation.

3. Which Defender product targets email threats?

Defender for Office 365.

4. What does threat intelligence add?

Context about adversaries, techniques and indicators.

5. Why review automated actions?

Incorrect scope or permissions can cause unnecessary disruption.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.