SC-200 Manage a security operations environment Practice Question
You have deployed Microsoft Defender for Endpoint and integrated it with Microsoft Sentinel. You notice that alerts from Defender for Endpoint are not appearing in Sentinel. What should you check first?
⚠ Common exam trap
The trap here is that candidates often jump to troubleshooting device onboarding or licensing, forgetting that the Sentinel connector is the explicit integration point that must be verified first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the Microsoft 365 Defender connector in Sentinel is enabled and configured.
The Microsoft 365 Defender connector in Microsoft Sentinel is the specific data connector responsible for ingesting alerts from Microsoft Defender for Endpoint (and other Defender products). If this connector is not enabled or misconfigured, alerts will not flow into Sentinel regardless of licensing, device onboarding, or analytics rules. This is the first and most direct check because the connector acts as the ingestion pipeline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify that the Microsoft 365 Defender connector in Sentinel is enabled and configured.
Why this is correct
The Microsoft 365 Defender connector is the data plane that carries M365 Defender alerts, including those from Defender for Endpoint, into Microsoft Sentinel. If this connector is not enabled in Sentinel's content hub and configured with the correct Microsoft 365 Defender workspace setting, no alerts will be streamed to the workspace. Since the symptoms point to missing alerts, verifying the connector's status and configuration is the primary and most direct troubleshooting step.
- ✗
Confirm that Defender for Endpoint is licensed for all users.
Why it's wrong here
Defender for Endpoint licensing is a tenant-level prerequisite for generating endpoint alerts in the first place, but it does not govern the outbound data flow to Microsoft Sentinel. The Microsoft 365 Defender connector pulls alerts from the unified Microsoft 365 Defender backend, so as long as the tenant is licensed and the service is deployed, the connector can stream alerts regardless of individual user licenses. Checking user licenses would only matter for user-level features, not for alert ingestion.
- ✗
Check that the alert severity is not being filtered out by analytics rules.
Why it's wrong here
Analytics rules in Sentinel do not filter the raw alert stream that comes through the Microsoft 365 Defender connector; they control which ingested events or alerts are turned into incidents. The connector itself has no default severity filter, so high and low severity alerts both appear in the Log Analytics workspace (e.g., SecurityIncident table). A custom analytics rule might suppress incident creation, but that would not cause the underlying alerts to be absent from the workspace, so severity filtering is not the root cause.
- ✗
Ensure that all devices are onboarded to Defender for Endpoint.
Why it's wrong here
Device onboarding determines whether an endpoint is actively monitored and can generate Defender for Endpoint alerts, but it has no effect on the connector's ability to stream those alerts once they exist in the Microsoft 365 Defender backend. If a device is not onboarded, it will not produce alerts, yet all alerts from onboarded devices should still flow to Sentinel through the connector. In a scenario where no alerts arrive at all, the failure lies upstream in the connector itself, not in the per-device onboarding state.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.