SC-200 Manage a security operations environment Practice Question
You need to ensure that Microsoft Sentinel can access threat intelligence feeds from external sources like AlienVault OTX. Which data connector should you use?
⚠ Common exam trap
Candidates often confuse the 'Threat Intelligence - TAXII' connector with other data connectors that also deal with external data (like AWS or Microsoft 365), but only the TAXII connector is specifically designed to ingest structured threat intelligence feeds using the STIX/TAXII standard.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat Intelligence - TAXII data connector
The Threat Intelligence - TAXII data connector is the correct choice because it enables Microsoft Sentinel to ingest threat intelligence feeds from external sources that support the TAXII (Trusted Automated eXchange of Indicator Information) protocol, such as AlienVault OTX. This connector uses the STIX (Structured Threat Information Expression) standard to pull indicators of compromise (IOCs) like IP addresses, domains, and hashes directly into Sentinel for correlation and alerting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft 365 Defender data connector
Why it's wrong here
The Microsoft 365 Defender data connector is designed to stream alerts, incidents, and advanced hunting events from Microsoft's security products (e.g., Microsoft Defender for Endpoint and Office 365) into Sentinel. While these alerts may include detection of known bad IPs or domains, the connector does not pull external threat-intelligence indicators from STIX/TAXII repositories. Therefore, it cannot be used to ensure Sentinel can access threat-intelligence feeds from third-party sources like AlienVault OTX.
- ✗
Microsoft Entra ID data connector
Why it's wrong here
The Microsoft Entra ID data connector ingests sign-in logs, audit logs, and provisioning events to provide identity-risk context. It is unrelated to web-based threat-intelligence feeds and does not support TAXII or STIX ingestion. Because it only collects Microsoft Entra ID activity, selecting it would leave Sentinel without an actual mechanism to consume external indicators of compromise (IOCs) from TAXII servers.
- ✗
Amazon Web Services data connector
Why it's wrong here
The Amazon Web Services data connector is intended to pull AWS CloudTrail and CloudWatch logs (and in some configurations GuardDuty findings) into Sentinel for threat hunting. It does not act as a client for TAXII 2.x servers and cannot fetch STIX packages containing malicious IPs, domains, or hashes from external intelligence providers. Thus, it serves operational telemetry but fails to establish the required threat-intelligence data pipeline.
- ✓
Threat Intelligence - TAXII data connector
Why this is correct
The Threat Intelligence - TAXII data connector is the correct choice because it enables Sentinel to connect directly to TAXII 2.x servers and ingest STIX-formatted threat-intelligence indicators (e.g., IP addresses, URLs, file hashes). This connector supports feeds such as AlienVault OTX. Once ingested, the indicators are stored in the ThreatIntelligenceIndicator table and can be used by analytics rules to correlate against logs and trigger incidents.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.