Courseiva

SC-200 Manage a security operations environment Practice Question

Which THREE components are required to implement a threat intelligence feed in Microsoft Sentinel using the Threat Intelligence - TAXII data connector?

⚠ Common exam trap

A common mix-up: candidates confuse the prerequisite (a Log Analytics workspace with Sentinel enabled) with a required component for the connector, or mistakenly think a watchlist is needed to store ingested threat indicators, when in fact the indicators are stored directly in the ThreatIntelligenceIndicator table.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Root collection ID

The root collection ID is a required component for the Threat Intelligence - TAXII data connector because it identifies the specific collection of threat indicators on the TAXII server. Without this ID, Microsoft Sentinel cannot determine which set of indicators to ingest, as a single TAXII server may host multiple collections. The connector uses the root collection ID to query the correct STIX/TAXII endpoint and retrieve the relevant threat intelligence feed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Root collection ID

    Why this is correct

    The Root collection ID is a mandatory parameter for the Microsoft Defender Threat Intelligence (MDTI) TAXII connector. It uniquely identifies the specific collection of threat intelligence indicators to be ingested, as a single TAXII 2.0 server can host multiple collections. Without this ID, the connector cannot determine which feed to pull from, even if the server URL and API key are correctly configured. This value is typically provided in the form of a UUID and is required to establish a successful data pull.

  • ✗

    A Log Analytics workspace with Microsoft Sentinel enabled

    Why it's wrong here

    A Log Analytics workspace with Microsoft Sentinel enabled is a global prerequisite for any data connector in Microsoft Sentinel, including the TAXII connector. However, it is not a component unique to implementing a threat intelligence feed and is not part of the TAXII connection parameters themselves. The workspace is the destination for the ingested indicators, but it does not participate in the authentication or collection selection logic of the TAXII protocol. Therefore, while necessary in practice, it is not one of the three required components specific to the TAXII connector configuration.

  • ✓

    TAXII server URL

    Why this is correct

    The TAXII server URL is a core component because it is the endpoint that the connector polls to retrieve threat intelligence. This URL follows the TAXII 2.0 or 2.1 API specification and must be publicly reachable from Azure. Without the correct URL, the connector cannot locate the server that hosts the collections. It is one of the three essential values you must supply when configuring the Microsoft Defender Threat Intelligence TAXII data connector.

  • ✓

    API key for the TAXII server

    Why this is correct

    An API key for the TAXII server is required for authentication, as the MDTI TAXII endpoints enforce token-based access control. This key is issued when you create an API resource in the Microsoft Defender Threat Intelligence portal, and it must be passed in the request headers to prove authorization. Without the API key, the server rejects the connection, so it is indispensable for establishing a successful data pull. It is distinct from the workspace key and from any Sentinel authentication, as it is specific to the TAXII provider.

  • ✗

    A watchlist named 'ThreatIntelligenceIndicators'

    Why it's wrong here

    A watchlist named 'ThreatIntelligenceIndicators' is not a requirement for the TAXII connector. Watchlists are custom collections of data used for correlation or enrichment in analytics rules, not for ingesting structured threat intelligence feeds. The TAXII connector writes indicators directly to the ThreatIntelligenceIndicator table in Log Analytics, without relying on a watchlist. Confusing watchlists with connector components is a common mistake, but the connector does not require or reference such a named watchlist.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.