Courseiva

SC-200 Respond to security incidents Practice Question

Which TWO are legitimate sources of threat intelligence that can be ingested into Microsoft Sentinel?

⚠ Common exam trap

Many candidates confuse security management tools (like EOP, Intune, or Compliance Manager) with actual threat intelligence sources, assuming any Microsoft security product can be a threat feed, whereas only dedicated CTI platforms or feeds (STIX/TAXII, Microsoft Defender Threat Intelligence) provide structured indicator ingestion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

STIX/TAXII threat intelligence feeds

A is correct because STIX/TAXII is an open-source standard for sharing cyber threat intelligence (CTI). Microsoft Sentinel can ingest threat indicators from any TAXII 2.0 or 2.1 server using the built-in Threat Intelligence - TAXII data connector, allowing organizations to consume structured threat feeds (e.g., from MITRE ATT&CK or third-party providers) directly into Sentinel for correlation and alerting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    STIX/TAXII threat intelligence feeds

    Why this is correct

    STIX/TAXII threat intelligence feeds are legitimate because STIX (Structured Threat Information eXpression) standardizes how threat indicators and malicious behaviors are described, while TAXII (Trusted Automated eXchange of Indicator Information) provides the standardized transport protocol for sharing those feeds. Microsoft Sentinel natively supports ingestion from TAXII servers via the Threat Intelligence TAXII data connector, allowing organizations to pull in indicators of compromise and campaign context from public or commercial providers. This standards-based interoperability is exactly why these feeds are a recognized, first-class source of threat intelligence in a SIEM.

  • ✓

    Microsoft Defender Threat Intelligence

    Why this is correct

    Microsoft Defender Threat Intelligence (MDTI) is a legitimate first-party threat intelligence source that aggregates global sensor data, Microsoft researcher analysis, vulnerability intelligence, and dark web monitoring into a single console. Sentinel can consume MDTI through the dedicated Microsoft Defender Threat Intelligence data connector or via the Microsoft Graph API, which enriches alerts with high-fidelity context such as actor attribution, kill-chain progression, and threat severity. Because MDTI is built into the Microsoft security ecosystem, its indicators and analytical reports are directly consumable for correlation and hunting, making it a valid TI source.

  • ✗

    Exchange Online Protection

    Why it's wrong here

    Exchange Online Protection (EOP) is a cloud-hosted email security service that delivers anti-malware, anti-spam, and anti-phishing filtering for Exchange Online mailboxes. While EOP internally consumes threat intelligence to make blocking decisions, it does not expose its internal indicators, reputation data, or detection heuristics as an exportable threat intelligence feed. Sentinel cannot connect to EOP as a threat intelligence source because EOP lacks an API or connector that provides raw TI indicators, only email transport and filtering event data.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is primarily a cloud-based unified endpoint management and mobile device management (MDM) service that enforces compliance policies, configures device profiles, and manages app protection. Although Intune can integrate with Microsoft Defender for Endpoint to receive device risk signals for conditional access, it does not generate, aggregate, or expose threat intelligence indicators, TTPs, or actor profiles. Intune's role is policy-driven device administration, not threat intelligence production, so it is not a legitimate source for Sentinel's Threat Intelligence feeds.

  • ✗

    Microsoft Purview Compliance Manager

    Why it's wrong here

    Microsoft Purview Compliance Manager is a governance and risk assessment solution that evaluates an organization's compliance against regulatory frameworks like GDPR and ISO 27001, providing scores, controls, and remediation actions. It does not collect, analyze, or distribute cyber threat intelligence such as malicious IP addresses, hashes, domains, or attacker behavior patterns. Because it completely lacks a mechanism to export indicators or integrate with Sentinel's Threat Intelligence connectors, it is categorically not a source of threat intelligence.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.