SC-100 Practice Question 3939

Exam: SC-100
Domain: Design security operations, identity, and compliance capabilities
Difficulty: medium
How does Microsoft Defender XDR correlate independent alerts from Defender for Endpoint, Defender for Office 365, and Defender for Identity into unified incidents?

Answer Options

A
Machine learning and automated correlation across identities, endpoints, and email
B
Manual sorting performed by external call center staff
C
Grouping alerts alphabetically by the first letter of the alert title
D
Random clustering based on server CPU utilization

Correct Answer

A: Machine learning and automated correlation across identities, endpoints, and email

Explanation

The Defender XDR correlation engine uses automated analytics and machine learning to link related alerts, impacted entities, and attack stages across domains into single holistic incidents.
SC-100 Practice Question 3939 – Design security operations, identity, and compliance capabilities