Courseiva

SC-200 Manage a security operations environment Practice Question

You are a Microsoft Security Operations Analyst. Your organization recently deployed Microsoft Defender for Cloud Apps. You need to ensure that alerts generated by Defender for Cloud Apps are automatically forwarded to Microsoft Sentinel. What should you configure?

⚠ Common exam trap

Test-takers frequently confuse the generic SIEM integration in Defender for Cloud Apps (which uses syslog or REST for third-party SIEMs) with the purpose-built Microsoft Sentinel data connector, leading them to select Option B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In Microsoft Sentinel, add the Microsoft Defender for Cloud Apps data connector.

The Microsoft Defender for Cloud Apps data connector in Microsoft Sentinel is the native integration that automatically forwards alerts and cloud discovery logs from Defender for Cloud Apps into Sentinel. This connector uses the Microsoft Graph Security API to ingest alerts without requiring additional configuration in Defender for Cloud Apps, enabling seamless correlation and investigation within Sentinel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    In Microsoft Sentinel, create an analytics rule with a query that pulls data from Defender for Cloud Apps API.

    Why it's wrong here

    Analytics rules in Microsoft Sentinel are designed to apply scheduled threat-detection queries against data that has already been ingested into the Log Analytics workspace. They cannot directly call the Defender for Cloud Apps API to pull historical or streaming data; instead, you must first bring that data into the workspace using a data connector. Creating an analytics rule here would result in no findings, because the underlying alert data would never be present.

  • ✗

    In Microsoft Defender for Cloud Apps, configure SIEM integration.

    Why it's wrong here

    In Microsoft Defender for Cloud Apps, SIEM integration is intended for forwarding alerts to third-party SIEM systems using a generic syslog format or via the SIEM agent. This integration does not natively write directly into a Microsoft Sentinel Log Analytics workspace; it requires additional configuration and still may not produce the rich, normalized data schema Sentinel expects. The officially supported and simpler path for Sentinel is to enable the dedicated Microsoft Defender for Cloud Apps data connector.

  • ✗

    In Microsoft Sentinel, configure a playbook to retrieve alerts from Defender for Cloud Apps.

    Why it's wrong here

    Playbooks in Microsoft Sentinel are based on Azure Logic Apps and are designed to automate incident response actions, such as containing a compromise or sending notifications, after an incident is created. They are not meant to be the primary data ingestion mechanism; using a playbook to manually retrieve alerts from Defender for Cloud Apps would be an inefficient workaround that lacks continuous ingestion and creates unnecessary latency. The correct approach is to use a data connector that continuously streams alerts and events into Sentinel.

  • ✓

    In Microsoft Sentinel, add the Microsoft Defender for Cloud Apps data connector.

    Why this is correct

    The Microsoft Defender for Cloud Apps data connector is the Microsoft-supported method for ingesting cloud app alerts, Cloud Discovery logs, and other security events directly into Microsoft Sentinel's Log Analytics workspace. This connector automatically streams data using the underlying Microsoft 365 Defender or standalone Defender for Cloud Apps APIs, making the information immediately available for analytics rules and workbooks. It provides the native schema and ensures proper correlation with other security data sources in Sentinel.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.