SC-200 Manage a security operations environment Practice Question
You are a security operations analyst for a company that uses Microsoft Sentinel. You need to ensure that all incidents created in the workspace are automatically enriched with threat intelligence indicators from Microsoft Defender Threat Intelligence. What should you configure?
⚠ Common exam trap
The trap here is thinking that a playbook or analytics rule is needed for enrichment, when the built-in MDTI connector provides automatic enrichment without custom automation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Microsoft Defender Threat Intelligence data connector in Microsoft Sentinel.
The Microsoft Defender Threat Intelligence data connector in Microsoft Sentinel ingests threat intelligence indicators into the workspace. Once enabled, Microsoft Sentinel automatically matches these indicators against incident entities, enriching incidents with relevant threat intelligence. This is the native and intended method for automatic enrichment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The Microsoft Defender Threat Intelligence data connector in Microsoft Sentinel.
Why this is correct
Microsoft Sentinel includes a data connector for Microsoft Defender Threat Intelligence (MDTI) that ingests threat intelligence indicators into the workspace. Once connected, these indicators are automatically used to enrich incidents, matching entities in incidents against the indicators. This provides native enrichment without custom automation. Configuring this connector is the correct method to ensure all incidents are enriched with MDTI indicators.
- ✗
A playbook that queries the Microsoft Defender Threat Intelligence API and adds indicators as comments to the incident.
Why it's wrong here
While a playbook can query external APIs and add comments, this approach is manual and reactive. It requires an automation rule to trigger the playbook for every incident, and the enrichment would be in the form of comments rather than native threat intelligence indicators. Microsoft Sentinel has a built-in connector for threat intelligence that automatically enriches incidents, making this custom approach unnecessary and less efficient.
- ✗
A workbook that visualizes threat intelligence matches for incidents.
Why it's wrong here
Workbooks are for visualization and reporting, not for automated enrichment. They can display data about incidents and threat intelligence, but they do not modify incidents or add indicators. The requirement is to automatically enrich incidents, which requires a data connector and the built-in enrichment logic, not a workbook. Thus, this option is incorrect.
- ✗
A scheduled analytics rule that runs every hour to match incidents with threat intelligence.
Why it's wrong here
Scheduled analytics rules are used to generate alerts based on queries, not to enrich existing incidents. They cannot automatically add threat intelligence indicators to incidents. While you could create a rule that generates new alerts based on matches, it would not enrich the original incidents. Therefore, this does not meet the requirement of automatic enrichment of all incidents.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.