Courseiva
mediumMultiple ChoiceObjective-mapped

SC-200 Practice Question: A security analyst is configuring a Microsoft…

A security analyst is configuring a Microsoft Sentinel playbook to automate the response to phishing incidents. When an incident is created based on a phishing analytics rule, the playbook needs to execute an action in Microsoft 365 Defender, such as blocking the sender email address. Which connector should the analyst add to the playbook to interact with Microsoft 365 Defender?

⚠ Common exam trap

It's easy for candidates to confuse the Microsoft 365 Defender connector with the Microsoft Entra ID connector, assuming identity actions can block email senders, but Entra ID lacks the email security APIs required for such remediation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft 365 Defender connector

The Microsoft 365 Defender connector is the correct choice because it provides the necessary actions to interact directly with Microsoft 365 Defender components, such as blocking a sender email address via the Advanced Hunting or action APIs. This connector enables the playbook to trigger remediation actions like email quarantine or sender block within the Microsoft 365 Defender portal, which is essential for automating responses to phishing incidents in Microsoft Sentinel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft 365 Defender connector

    Why this is correct

    The Microsoft 365 Defender connector is the correct choice because it is purpose-built for security response actions in Microsoft 365 Defender, including blocking email senders, isolating compromised devices, and running advanced hunting queries. It is implemented as a Logic Apps managed connector that uses the Microsoft 365 Defender APIs, allowing playbooks to initiate remediation directly from Sentinel incidents.

  • Microsoft Entra ID connector

    Why it's wrong here

    The Microsoft Entra ID connector is incorrect because its actions target identity and access management, such as updating user profiles, assigning licenses, or managing group memberships. It does not expose Microsoft 365 Defender security actions like device isolation or email sender blocking, so using it in a playbook would not achieve the desired remediation outcome.

  • Azure DevOps connector

    Why it's wrong here

    The Azure DevOps connector is incorrect because it is designed for software development workflows, enabling actions like creating work items, managing builds, and controlling releases. While a playbook could log a security incident as a work item, it cannot interact with Microsoft 365 Defender to execute security remediation such as blocking threats or isolating endpoints.

  • Teams connector

    Why it's wrong here

    The Teams connector is incorrect because it is used for collaboration and communication, allowing playbooks to post messages, send notifications, or create chat channels. Although sending a Teams alert is a common incident response step, the connector lacks native actions that can call Microsoft 365 Defender to block senders or isolate devices, so it cannot perform the required remediation.

About these practice questions

One of 209 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.