SC-200 Respond to security incidents Practice Question
Which THREE resources can be used as data sources for Microsoft Sentinel to detect security incidents? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft 365 Defender
Options A, B, and C are correct. Microsoft 365 Defender provides integrated threat signals across endpoints, email, and identities. Microsoft Defender for Cloud delivers security alerts and posture assessments for cloud workloads. Azure Activity Log captures subscription-level operational events, which can be streamed to Sentinel. Option D is incorrect because Azure Cost Management focuses on cost tracking and budgeting, not security events. Option E is incorrect because Azure Advisor provides optimization recommendations, not security incident data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft 365 Defender
Why this is correct
Microsoft 365 Defender is a valid data source because its built-in connector streams unified alerts and incidents from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps into Microsoft Sentinel. These security signals include attacker activities, malware events, and phishing detections, which are mapped directly to Sentinel's incident schema for correlation and investigation.
- ✓
Microsoft Defender for Cloud
Why this is correct
Microsoft Defender for Cloud serves as a data source by continuously reporting security posture, regulatory compliance, and workload protection alerts from across Azure, on-premises, and other clouds. Its connector in Sentinel ingests security alerts and assessment recommendations, giving SecOps a centralized view of vulnerable resources and active threats in hybrid environments.
- ✓
Azure Activity Log
Why this is correct
The Azure Activity Log is a subscription-level platform log that records all management-plane operations (create, update, delete, and access operations) for Azure resources. When connected to Sentinel via a diagnostic setting or the standard Activity Log connector, it supplies invaluable write-activity telemetry for detecting suspicious administrative actions, privilege changes, or unauthorized resource modifications.
- ✗
Azure Cost Management
Why it's wrong here
Azure Cost Management is not a security data source because it only provides financial management and cost-optimization telemetry, such as spending limits, budgets, and resource usage cost. Its data lacks threat indicators, security event properties, or user-driven security-investigation context, and Microsoft Sentinel has no valid connector to ingest Cost Management outputs as operational security data.
- ✗
Azure Advisor
Why it's wrong here
Azure Advisor is fundamentally a recommendation engine, not a telemetry source; it analyzes configurations and usage to suggest best practices for cost, performance, reliability, and security. While it may surface security recommendations, it does not generate streamable raw security events, alert logs, or incident timelines, so it cannot be used as a data source for SIEM ingestion in Sentinel.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.