SC-200 Manage a security operations environment Practice Question
Which TWO of the following are required to enable Microsoft Sentinel to receive alerts from Microsoft Defender for Cloud? (Choose two.)
⚠ Common exam trap
A common mix-up: candidates confuse enabling Defender for Cloud at the subscription level (which is required) with deploying agents or policies, thinking those are prerequisites for alert ingestion, when in fact the connector handles the ingestion independently of agent deployment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install the 'Microsoft Defender for Cloud' data connector in Microsoft Sentinel.
The 'Microsoft Defender for Cloud' data connector in Microsoft Sentinel is the specific integration point that ingests security alerts from Defender for Cloud into Sentinel. Without installing and configuring this connector, Sentinel cannot receive the alerts, even if Defender for Cloud is enabled on the subscription.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy the Log Analytics agent on all VMs.
Why it's wrong here
Deploy the Log Analytics agent on all VMs. — The Microsoft Defender for Cloud data connector pulls alerts via the Defender for Cloud API, not by reading data from the Log Analytics agent. While the agent can help Defender for Cloud collect VM-focused signals for certain detections, Sentinel's connector ingests already-generated security alerts from the Defender for Cloud resource provider. Thus, deploying the agent on every VM is not a prerequisite for enabling Defender for Cloud alerts in Sentinel.
- ✗
Connect a non-Azure machine using Azure Arc.
Why it's wrong here
Connect a non-Azure machine using Azure Arc. — This scenario involves only Azure VMs and the subscription-level integration; there is no requirement to onboard any on-premises or other-cloud machines via Azure Arc. Arc is a separate management plane for hybrid resources, and while Defender for Cloud can extend protections to Arc-connected machines, it is not needed for enabling alerts from an Azure subscription. The connector works directly with Defender for Cloud on Azure, without any Arc dependency.
- ✓
Install the 'Microsoft Defender for Cloud' data connector in Microsoft Sentinel.
Why this is correct
Install the 'Microsoft Defender for Cloud' data connector in Microsoft Sentinel. — To route Defender for Cloud alerts into Sentinel, you must install and configure the Microsoft Defender for Cloud data connector in the Sentinel workspace. This connector establishes the API integration and subscription selection that streams alerts into the SecurityAlert table. Without this connector, Sentinel has no pipeline to receive those alerts, even if Defender for Cloud is enabled.
- ✓
Enable Microsoft Defender for Cloud on the Azure subscription.
Why this is correct
Enable Microsoft Defender for Cloud on the Azure subscription. — Microsoft Defender for Cloud must be active on the subscription because it is the service that generates the security alerts that Sentinel will ingest. Alerts do not appear in the connector unless Defender for Cloud has been enabled and is producing findings. Enabling it is the foundational prerequisite for the entire alert pipeline; the connector only facilitates the transfer.
- ✗
Assign an Azure Policy to enable Defender for Cloud.
Why it's wrong here
Assign an Azure Policy to enable Defender for Cloud. — Using Azure Policy to enable Defender for Cloud is an optional governance automation, not a technical requirement. You can manually enable Defender for Cloud on the subscription, which is sufficient for the connector to retrieve alerts. Policy assignment only helps enforce this setting across many subscriptions and does not introduce any additional step in the Defender-for-Cloud-to-Sentinel data flow.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.