Courseiva

SC-200 Respond to security incidents Practice Question

Which THREE are valid data connectors in Microsoft Sentinel for ingesting security events from Microsoft 365 services? (Choose three.)

⚠ Common exam trap

Many candidates confuse Microsoft Purview (a compliance tool) with a security event source, or think Intune's device management logs qualify as 'security events from Microsoft 365 services' when Sentinel's Intune connector is actually for device compliance data, not security events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft 365 Defender

Microsoft 365 Defender is a valid data connector in Microsoft Sentinel that ingests alerts and incidents from Microsoft 365 Defender components (Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps). It uses the Microsoft 365 Defender API to pull correlated security events, enabling centralized investigation of advanced threats across the M365 ecosystem.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft 365 Defender

    Why this is correct

    Microsoft 365 Defender is a native Sentinel data connector that ingests high-fidelity alerts and incidents from the Microsoft Defender XDR suite, including Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. This connector enables cross-domain correlation and automates incident response by bringing unified XDR telemetry directly into Sentinel, making it a core component for modern security operations.

  • ✗

    Microsoft Purview

    Why it's wrong here

    Microsoft Purview is not a data connector; it is a comprehensive compliance and governance platform covering data loss prevention, eDiscovery, and insider risk management. Sentinel does not provide a direct Purview connector, so Purview-related data must be routed to Log Analytics via diagnostic settings or collected indirectly through other connectors such as Office 365 or Azure Activity, rather than appearing as a native data source.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is a cloud-based mobile device management (MDM) and mobile application management (MAM) service, but it is not a directly listed data connector in Sentinel. Intune-generated logs, such as device compliance reports and configuration events, are typically ingested through diagnostic settings to a Log Analytics workspace or surface via other connectors like Microsoft Entra ID sign-in logs and Office 365 audit logs, requiring an intermediary pipeline rather than a native connector.

  • ✓

    Microsoft Entra ID

    Why this is correct

    Microsoft Entra ID is a valid Sentinel connector that ingests sign-in logs, audit logs, and provisioning logs from Microsoft Entra ID (now Microsoft Entra ID). This connector provides crucial identity telemetry for detecting brute-force attacks, impossible travel, and other sign-in anomalies. It is often paired with analytics rules that trigger on risky sign-ins and other identity-based threats, making it essential for identity-focused security monitoring.

  • ✓

    Office 365

    Why this is correct

    Office 365 is a built-in Sentinel data connector that collects unified audit logs from Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams. It leverages the Office 365 Management Activity API and requires an appropriate admin role, such as Global Admin or Security Admin, for configuration. This connector is vital for monitoring user activity across productivity workloads and is commonly used for insider threat and compromised account investigations.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.