Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

A company uses Microsoft Sentinel to centralize security logs. They need to ensure that incidents from Microsoft Defender XDR are synchronized into Sentinel. Which data connector should they enable?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender XDR connector

The Microsoft Defender XDR connector (option C) is the correct choice because it is the built-in Microsoft Sentinel data connector designed to ingest and synchronize incidents and alerts from Microsoft Defender XDR into Sentinel, enabling unified incident management across Defender products. The Office 365 connector (option A) only ingests Office 365 audit and activity logs, not Defender XDR incidents. The Windows Security Events connector (option B) collects Windows event logs from agents, and the Azure Activity connector (option D) ingests Azure subscription control-plane activity, neither of which synchronizes Defender XDR incidents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Office 365 connector

    Why it's wrong here

    The Office 365 connector is built to ingest Office 365 audit logs, including Exchange Online, SharePoint Online, Microsoft Teams, and Microsoft Entra ID sign-in events, via the Office Management API. These logs are user and admin activity records, not the outcome of the correlated threat detection that produces Defender XDR incidents. While Defender XDR incidents may include alerts generated from Office 365 data, the Office 365 connector alone will not bring the aggregated incident object. To pull the actual Defender XDR incidents, you must use the dedicated Microsoft Defender XDR connector.

  • ✗

    Windows Security Events connector

    Why it's wrong here

    The Windows Security Events connector is designed to stream raw Windows Event Logs (Security, System, Application) from servers and workstations into Microsoft Sentinel via the Log Analytics agent (MMA/AMA). It provides raw OS-level telemetry such as logon events, process creation, and privilege escalation, but it does not ingest Microsoft Defender XDR incidents, which are already correlated alerts from multiple Defender services. Even if you enable it, you would only get individual event records, not the unified incident entities that Defender XDR generates. Therefore, it cannot be used to centralize Defender XDR incidents.

  • ✓

    Microsoft Defender XDR connector

    Why this is correct

    The Microsoft Defender XDR connector is the correct data connector to centralize security incidents in Microsoft Sentinel. It connects to the Microsoft Graph Security API and imports incidents and alerts from all Defender XDR workloads—Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps—into Sentinel. This connector keeps incident status, severity, and classification synchronized bidirectionally, so you can manage the full incident lifecycle from Sentinel. Without this connector, Defender XDR incidents would not appear in Sentinel at all, making it the only option that directly satisfies the requirement.

  • ✗

    Azure Activity connector

    Why it's wrong here

    The Azure Activity connector collects the Azure subscription-level activity logs that capture control-plane operations, such as virtual machine creation, Azure Resource Manager resource changes, and role-based access control assignments. This connector is meant for monitoring Azure resource management audit trails, not for ingesting security incidents or alerts from Microsoft Defender XDR. Even if a Defender XDR incident pertains to an Azure resource, the Azure Activity connector will not deliver that incident to Sentinel. The correct path for importing Defender XDR incidents is the Microsoft Defender XDR connector, which uses the Graph Security API.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.