Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization has recently deployed Microsoft Sentinel and wants to ensure that all critical Azure resources are monitored for security misconfigurations. You have already enabled Microsoft Defender for Cloud on all subscriptions. You need to configure a solution that will automatically create a Sentinel incident whenever a new security recommendation with severity 'High' is generated in Defender for Cloud. The incident should be assigned to the 'Infrastructure' team. Additionally, you want to run a playbook that will open a ticket in your IT Service Management (ITSM) tool. What should you do?

⚠ Common exam trap

It's easy for candidates to think they need to write a custom analytics rule (Option C) or use the Azure Activity connector (Option A) to ingest Defender for Cloud data, when in fact the Defender for Cloud connector already provides incident creation and automation rules handle assignment and playbook execution natively.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the Defender for Cloud connector, then create an automation rule that triggers on incident creation from the connector, assigns to 'Infrastructure', and runs a playbook.

The Defender for Cloud connector in Microsoft Sentinel ingests security recommendations and alerts as incidents. By creating an automation rule that triggers on incident creation from this connector, you can automatically assign incidents to the 'Infrastructure' team and run a playbook to open a ticket in your ITSM tool, fulfilling all requirements without custom queries or workbooks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the Azure Activity connector to ingest recommendations, then create an analytics rule to generate incidents.

    Why it's wrong here

    Azure Activity connector ingests subscription-level operational events and audit trails (e.g., resource creation, configuration changes), not security control recommendations from Defender for Cloud. Recommendations such as missing MFA or vulnerability findings are not emitted as Activity logs, so an analytics rule built on that connector would have no relevant data to generate incidents. Therefore, this approach would fail to ingest any security recommendations, making it ineffective for the given requirement.

  • ✗

    Enable the Defender for Cloud connector and create a workbook to monitor recommendations.

    Why it's wrong here

    Although enabling the Defender for Cloud connector does ingest security recommendations and alerts into Sentinel, a workbook only provides a visual dashboard over the data for monitoring and reporting. Workbooks do not generate incidents or trigger automated responses; they are entirely passive analytics layers. Thus, while the connector part is correct, creating a workbook does not satisfy the need to generate incidents or remediate the discovered recommendations.

  • ✗

    Create a custom analytics rule that queries the SecurityRecommendation table in the Log Analytics workspace.

    Why it's wrong here

    The SecurityRecommendation table is populated in the Log Analytics workspace only after you enable the Microsoft Defender for Cloud data connector; in a fresh Sentinel deployment without that connector, queries against this table return no rows. Even if data were present, a custom analytics rule would simply create alerts from the query results, without automatically assigning the incident to the Infrastructure team or invoking a playbook for remediation. The requirement calls for both incident generation and an automated response workflow, which this option only partially addresses.

  • ✓

    Enable the Defender for Cloud connector, then create an automation rule that triggers on incident creation from the connector, assigns to 'Infrastructure', and runs a playbook.

    Why this is correct

    Enabling the Defender for Cloud connector is the prerequisite to bring security recommendations and leading alerts into Sentinel as incidents through its built-in analytics rule. A subsequent automation rule that triggers when an incident is created can be configured to assign the incident to the Infrastructure team (using a specific owner or group) and run a playbook to automate the recommended remediation. This design fully satisfies the requirement: data is ingested, incidents are generated, and an automated response is applied based on the recommendation.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.