SC-200 Manage a security operations environment Practice Question
Your organization plans to implement Microsoft Sentinel. Which THREE components are required for a basic deployment? (Choose three.)
⚠ Common exam trap
The trap here is that candidates often mistake optional advanced features like UEBA or bookmarks as required components, when in fact only the workspace, a data connector, and analytics rules are necessary to establish a basic, functional Sentinel deployment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analytics rules to generate incidents.
Analytics rules are required to generate incidents from the data ingested into Microsoft Sentinel. Without analytics rules, the raw log data remains unprocessed and no security incidents are created, making the deployment non-functional for detection and response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
User and Entity Behavior Analytics (UEBA) enabled.
Why it's wrong here
User and Entity Behavior Analytics (UEBA) is an optional add-on in Microsoft Sentinel that helps detect anomalies by profiling user and entity behavior. It enriches entities and provides evidence for investigations, but it is not required to generate incidents. Disabling UEBA does not prevent analytics rules from creating incidents; it only reduces the behavioral context available during analysis.
- ✓
Analytics rules to generate incidents.
Why this is correct
Analytics rules are the core detection mechanism in Microsoft Sentinel that turn raw alerts into actionable incidents. To generate incidents, you must configure at least one analytics rule with incident creation enabled, using a KQL query to match threats. Without these rules, even with data ingested, Sentinel cannot automatically create security incidents.
- ✓
At least one data connector enabled.
Why this is correct
A data connector is mandatory for Microsoft Sentinel to ingest security events from sources like Microsoft Entra ID, Azure Activity, or third-party tools. It brings raw logs into the Log Analytics workspace, providing the input that analytics rules need to detect threats. However, a connector alone does not generate incidents; analytics rules are still required to translate alerts into incidents.
- ✗
Bookmarks for incident investigations.
Why it's wrong here
Bookmarks are an optional feature in Microsoft Sentinel used to preserve and annotate specific log entries during proactive threat hunting. They allow analysts to group interesting events for later investigation, but they do not automate incident creation or influence analytics rule execution. Bookmarks are helpful for manual analysis, not for the core detection pipeline.
- ✓
A Log Analytics workspace.
Why this is correct
A Log Analytics workspace is the fundamental storage and query engine on which Microsoft Sentinel is built. Every piece of data, including security logs, alerts, and incidents, resides in this workspace, and Sentinel cannot be enabled without a designated one. It is a mandatory prerequisite for implementation and serves as the back end for all KQL queries used by analytics rules.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.