easyMultiple ChoiceObjective-mapped
SC-200 Practice Question: A company uses Microsoft Defender for Cloud to…
A company uses Microsoft Defender for Cloud to secure its Azure environment. The security team wants to receive notifications via email whenever a high-severity security alert is generated. What should they configure in Defender for Cloud?
⚠ Common exam trap
Watch out — candidates often confuse the purpose of 'Continuous Export' (which is for data export, not direct notification) or assume that Azure Monitor alert rules are the universal mechanism for all Azure alerts, overlooking Defender for Cloud's dedicated email notification settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set up email notifications for high-severity alerts in the Defender for Cloud environment settings.
Defender for Cloud provides a built-in email notification configuration specifically for security alerts. By navigating to the 'Environment settings' for the subscription or management group, then selecting 'Email notifications', you can enable and configure alerts to be sent to specified recipients when high-severity alerts are generated. This is the direct, purpose-built method for email notification of Defender for Cloud alerts without requiring additional services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the 'Continuous Export' feature to send alerts to a Log Analytics workspace.
Why it's wrong here
Continuous Export in Microsoft Defender for Cloud is designed to stream security alerts and recommendations to a Log Analytics workspace or Event Hub for long-term retention, integration with SIEMs, or custom analytics. It does not have any native capability to generate email notifications; it merely forwards raw data for downstream processing. Therefore, while it can help centralize alert data, it is not the appropriate mechanism to directly email security personnel about high-severity alerts.
- ✗
Configure an alert rule in Azure Monitor.
Why it's wrong here
Azure Monitor alert rules are a general-purpose alerting mechanism for metrics and logs across Azure resources, and they can be configured to send emails. However, Defender for Cloud already generates its own security alerts and provides a dedicated, built-in email notification feature that is managed within the Defender for Cloud environment settings. Using Azure Monitor would require creating duplicate rules and manually mapping alert conditions, which is unnecessary and less integrated than using the native Defender for Cloud email configuration, making it a suboptimal choice for this requirement.
- ✓
Set up email notifications for high-severity alerts in the Defender for Cloud environment settings.
Why this is correct
In Microsoft Defender for Cloud, the correct way to receive email notifications for high-severity alerts is to navigate to the environment settings, select the subscription's settings, and then configure the email notifications pane. There you can specify security contact email addresses and choose the severity levels (e.g., high severity) for which notifications should be sent. This native feature is purpose-built for directly alerting security teams via email when critical vulnerabilities are detected, ensuring timely awareness without relying on external workflows.
- ✗
Create an automation rule in Microsoft Sentinel.
Why it's wrong here
Microsoft Sentinel automation rules are used to trigger automated responses—such as creating incidents, assigning owners, or running playbooks—based on analytics rules or incidents, not to forward Defender for Cloud alerts via email. While Sentinel can ingest Defender for Cloud alerts and orchestrate email via Logic Apps, that approach is far more complex and indirect than the simple, native email notification settings available directly in Defender for Cloud. The question specifically asks about Defender for Cloud's capabilities, so an automation rule in Sentinel is not the correct solution for sending email alerts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.