SC-200 Manage a security operations environment Practice Question
Your company uses Microsoft Sentinel and has enabled the Microsoft Defender XDR connector. You notice that incidents from Microsoft Defender for Cloud Apps are not appearing in Microsoft Sentinel. All other Defender XDR incidents appear correctly. What is the most likely cause?
⚠ Common exam trap
Test-takers frequently assume the Microsoft Defender XDR connector automatically ingests incidents from all Defender products, but in reality, each product requires its own data connector to be enabled in Microsoft Sentinel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Microsoft Defender for Cloud Apps data connector is not enabled in Microsoft Sentinel.
The Microsoft Defender XDR connector ingests incidents from all Microsoft Defender products, including Defender for Cloud Apps, but only if the corresponding data connector is enabled in Microsoft Sentinel. Option D is correct because the Microsoft Defender for Cloud Apps data connector must be explicitly enabled to allow incident ingestion from that source; without it, incidents from Defender for Cloud Apps will not appear even though the XDR connector is active.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The security operations team does not have the appropriate permissions.
Why it's wrong here
In Microsoft Sentinel, RBAC roles determine which users can view, investigate, and respond to incidents, but they do not control data ingestion. The Defender for Cloud Apps connector runs as a background service using service-to-service authentication, not as an action performed by a signed-in user. Even if the security operations team lacks any Sentinel permissions, incidents would still be ingested as long as the connector is enabled; conversely, granting the 'Security Reader' role would not create missing incidents. Therefore, permissions are not the root cause.
- ✗
The Microsoft Defender XDR connector only ingests incidents from Microsoft Defender for Endpoint.
Why it's wrong here
This statement is factually incorrect—the Microsoft Defender XDR connector ingests incidents from the entire Microsoft 365 Defender suite, including Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. It uses the unified Microsoft 365 Defender API to correlate alerts and incidents across these workloads. The connector is not limited to Endpoint, and disabling it would affect incidents from all Defender components. However, even with this connector enabled, incidents that originate directly in Defender for Cloud Apps may require the dedicated Cloud Apps connector to be fully ingested, so the XDR connector's scope is broader than this option claims.
- ✗
The Microsoft 365 E5 license is not assigned to the users.
Why it's wrong here
A Microsoft 365 E5 license is a prerequisite for users to generate alerts in Defender for Cloud Apps, but license assignment does not control connector enablement in Sentinel. The Sentinel connector authenticates to the underlying service at the workspace level, not per user, and it will ingest incidents regardless of whether a specific analyst has E5 assigned. If the connector is disabled, incidents are silently dropped even for fully licensed users. Licensing might affect the volume or types of logs generated, but it cannot cause missing incidents when the connector itself remains off and unconfigured.
- ✓
The Microsoft Defender for Cloud Apps data connector is not enabled in Microsoft Sentinel.
Why this is correct
Microsoft Defender for Cloud Apps has its own dedicated data connector in Microsoft Sentinel, and it must be explicitly enabled through the Sentinel data connectors page or content hub. Without this connector, Sentinel has no API subscription to Defender for Cloud Apps, so incidents, alerts, and cloud discovery logs are not imported. Enabling the Microsoft Defender XDR connector alone does not guarantee delivery of all Cloud Apps incidents—the two connectors subscribe to different data streams. Thus, the missing Cloud Apps incidents are exactly what would be observed when this connector has not been turned on.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your company has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You recently deployed Microsoft Defender for Identity (MDI) to monitor on-premises domain controllers. The SOC team needs to receive alerts from MDI in Microsoft Sentinel. You have already installed the MDI sensor on all domain controllers and confirmed that the MDI portal shows alerts. However, no MDI alerts appear in Sentinel. The Microsoft Defender for Identity data connector in Sentinel shows 'Connected'. What should you do next?
medium- A.Update the MDI sensor to the latest version.
- ✓ B.Enable the Microsoft 365 Defender connector in Sentinel, as MDI alerts are ingested through that connector.
- C.Reconfigure the MDI data connector to select all alert severities.
- D.Check the MDI sensor health status on each domain controller.
Why B: Microsoft Defender for Identity alerts are surfaced in Microsoft Sentinel through the Microsoft 365 Defender connector (or the Microsoft Defender XDR connector), not solely through the standalone MDI data connector. Even when the MDI connector shows 'Connected', alert ingestion into Sentinel requires the Microsoft 365 Defender connector to be enabled so that MDI alerts flow through the unified XDR pipeline.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.