SC-200 Respond to security incidents Practice Question
A SOC team uses Microsoft Sentinel and wants to automatically enrich incidents with threat intelligence from a third-party feed. Which feature should they configure to ingest the threat intelligence and correlate it with alerts?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat intelligence connectors
Threat intelligence connectors in Microsoft Sentinel allow ingestion of TI feeds and enable correlation with alerts. The other options do not provide this capability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Analytics rules
Why it's wrong here
Analytics rules are detection queries that can reference the ThreatIntelligenceIndicator table to match events, but they do not ingest or import TI data themselves. They depend on a threat intelligence connector having already populated the workspace with indicators from external feeds. Without that connector, there is no TI data for the rule to query against, so they cannot satisfy the requirement to automatically import and correlate TI feeds.
- ✓
Threat intelligence connectors
Why this is correct
Threat intelligence connectors are purpose-built data connectors that pull indicators from external sources—such as TAXII feeds, Microsoft Defender Threat Intelligence, or third-party platforms—directly into the normalized ThreatIntelligenceIndicator table. Once ingested, Sentinel automatically enables matching and correlation across analytics rules and detections. This is the correct mechanism for automatically importing and operationalizing TI feeds.
- ✗
Data connectors
Why it's wrong here
Data connectors in Microsoft Sentinel ingest raw log and event data from sources such as syslog, CEF or AWS services; they do not perform threat-intelligence matching or indicator enrichment on their own. Enriching incidents with third-party indicators requires the Threat Intelligence Platforms connector plus the matching analytics rule, which correlates indicators with alerts.
- ✗
Watchlists
Why it's wrong here
Watchlists are locally managed, CSV-based collections used for enrichment or custom detection and are uploaded either manually or via custom automation—they are not automatically fed by external TI providers. They are not integrated into Sentinel's TI correlation pipeline and require an analytics rule to reference the watchlist for any matching. Because they lack the automatic ingestion and normalization functionality of TI connectors, they cannot meet the requirement for automatic TI correlation.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.