Courseiva
mediumDrag & Drop

SC-200 Practice Question: Order the steps to set up a Microsoft Sentinel…

Order the steps to set up a Microsoft Sentinel workspace and connect Microsoft 365 Defender data.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

1. Create a Log Analytics workspace. 2. Enable Microsoft Sentinel on the workspace. 3. Configure the Microsoft 365 Defender data connector. 4. Verify data ingestion and alerts.

Sentinel is enabled on a Log Analytics workspace, then data connectors like M365 Defender are configured to ingest data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    1. Create a Log Analytics workspace. 2. Enable Microsoft Sentinel on the workspace. 3. Configure the Microsoft 365 Defender data connector. 4. Verify data ingestion and alerts.

    Why this is correct

    This is the correct order because you need a Log Analytics workspace to host Sentinel, then you enable Sentinel on it, then you can configure data connectors like Microsoft 365 Defender to ingest data, and finally verify that data flows correctly.

  • ✗

    1. Create a Log Analytics workspace. 2. Configure the Microsoft 365 Defender data connector. 3. Enable Microsoft Sentinel on the workspace. 4. Verify data ingestion and alerts.

    Why it's wrong here

    This sequence attempts to configure the Microsoft 365 Defender data connector immediately after creating the Log Analytics workspace but before enabling Microsoft Sentinel. The connector is accessed through the Microsoft Sentinel portal, and its prerequisites include an active Sentinel workspace because it ingests alerts, incidents, and raw events into Sentinel tables such as SecurityAlert and DeviceEvents. Since Microsoft Sentinel has not been enabled on the workspace, the connector configuration wizard is not available, so the ordering fails at step 2.

  • ✗

    1. Enable Microsoft Sentinel on the workspace. 2. Create a Log Analytics workspace. 3. Configure the Microsoft 365 Defender data connector. 4. Verify data ingestion and alerts.

    Why it's wrong here

    This order tries to enable Microsoft Sentinel before any Log Analytics workspace exists. Enabling Sentinel is a process that requires you to either select an existing workspace or create a new one, because Sentinel is built on top of a workspace and uses its underlying storage, retention, and KQL query scope. Without a workspace at step 1, this sequence is invalid from the outset — the portal simply will not allow you to onboard Sentinel without a workspace to bind it to.

  • ✗

    1. Configure the Microsoft 365 Defender data connector. 2. Create a Log Analytics workspace. 3. Enable Microsoft Sentinel on the workspace. 4. Verify data ingestion and alerts.

    Why it's wrong here

    Putting the Microsoft 365 Defender data connector first is fundamentally reversed: the connector requires both a Log Analytics workspace and Microsoft Sentinel to already be enabled and configured. If you try to configure the connector before creating a workspace, there are no Log Analytics tables (for example, SecurityAlert, DeviceEvents, IdentityLogonEvents) to store the incoming Microsoft 365 Defender data, and the connector UI is not available because Sentinel is not onboarded. The entire workflow is out of order, so step 1 cannot be completed at all.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.