SC-200 Manage a security operations environment Practice Question
Your organization has recently deployed Microsoft Sentinel and Microsoft Defender XDR. You are tasked with configuring the environment to ensure that incidents created by Microsoft Defender for Cloud Apps are automatically synchronized to Microsoft Sentinel. The security operations team wants to manage all incidents from within Sentinel. You have already connected the Microsoft Defender XDR connector to Sentinel. However, you notice that incidents from Defender for Cloud Apps are not appearing in Sentinel. You verify that the Defender for Cloud Apps connector is not listed in the data connectors blade. What should you do to resolve this issue?
⚠ Common exam trap
Watch out — candidates often assume each Microsoft Defender product requires its own dedicated data connector in Sentinel, when in fact the Microsoft Defender XDR connector serves as the unified ingestion point for all Defender incidents, including those from Defender for Cloud Apps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the Microsoft Defender XDR connector is configured to include Defender for Cloud Apps incidents.
When Microsoft Defender XDR connector is enabled in Sentinel, it can ingest incidents from all Microsoft Defender products, including Defender for Cloud Apps, provided the connector's configuration includes the option to synchronize those incidents. Since the Defender for Cloud Apps connector is not listed separately, the correct approach is to verify and adjust the Microsoft Defender XDR connector's settings to include Defender for Cloud Apps incidents. Option D directly addresses this by ensuring the existing connector is configured to forward those incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the Microsoft Sentinel integration in the Defender for Cloud Apps portal.
Why it's wrong here
Enabling the Microsoft Sentinel integration in the Defender for Cloud Apps portal is redundant when the Defender XDR connector is already connected, because that integration simply configures a direct SIEM API connection that sends alerts to Sentinel separately. This legacy method requires creating a token, configuring a SIEM agent, and can lead to duplicate incidents and data ingestion costs. The Defender XDR connector already consumes Defender for Cloud Apps incidents automatically, so no additional action is needed in the portal.
- ✗
Configure a data collection rule in Microsoft Purview to forward alerts to Sentinel.
Why it's wrong here
Configuring a data collection rule in Microsoft Purview to forward alerts to Sentinel is invalid because Purview is a governance and compliance tool that manages data maps, labels, and retention, not a security alert pipeline. Sentinel ingests alerts and incidents through specific data connectors or Log Analytics workspaces; DCRs are used in Azure Monitor to collect telemetry from resources, not to forward Defender for Cloud Apps alerts. There is no Purview-to-Sentinel forwarding mechanism for security alerts, so this action would have no effect on incident ingestion.
- ✗
Install the Microsoft Defender for Cloud Apps connector from Sentinel data connectors.
Why it's wrong here
There is no standalone 'Microsoft Defender for Cloud Apps' data connector in the Sentinel data connectors gallery, so attempting to install one is impossible. Instead, Defender for Cloud Apps incidents are included in the Microsoft Defender XDR (formerly Microsoft 365 Defender) connector, which aggregates incidents from all Microsoft security services. The correct approach is to enable that unified connector rather than look for a separate Cloud Apps connector, which only exists as a legacy API-based connection method that is not listed in the gallery.
- ✓
Ensure the Microsoft Defender XDR connector is configured to include Defender for Cloud Apps incidents.
Why this is correct
The proper way to ingest Defender for Cloud Apps incidents is to ensure the Microsoft Defender XDR data connector is enabled in Sentinel and that the 'Microsoft Defender for Cloud Apps' incident table is checked in its configuration. This connector automatically synchronizes incidents from Defender XDR—which include alerts and incidents generated by Defender for Cloud Apps—into Sentinel without any additional setup. As long as the connector shows a connected status and the correct product is selected, Cloud Apps incidents will flow directly to Sentinel's 'Incidents' blade.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.