SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. You need to ensure that anomalous behavior alerts from Defender for Cloud Apps are automatically converted to incidents in Sentinel. What should you configure?
⚠ Common exam trap
Many candidates confuse the purpose of data connectors—assuming any Microsoft security connector (like Defender for Identity or Microsoft 365) will ingest all security alerts, when in fact each connector is scoped to its specific product's data source.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the Microsoft Defender for Cloud Apps data connector in Microsoft Sentinel.
The Microsoft Defender for Cloud Apps data connector in Microsoft Sentinel is specifically designed to ingest alerts and anomalies from Defender for Cloud Apps and automatically create SecurityIncident records in Sentinel. Enabling this connector ensures that anomalous behavior alerts are converted to incidents without requiring custom playbooks or additional logic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the Microsoft Defender for Identity data connector in Microsoft Sentinel.
Why it's wrong here
Enabling the Microsoft Defender for Identity data connector in Microsoft Sentinel ingests security signals from on-premises Active Directory, such as suspected lateral movement, pass-the-hash, and entity behavioral alerts. It does not connect to the Defender for Cloud Apps service, so it cannot bring in alerts about shadow IT, anomalous cloud app usage, or other cloud application activities. This option would address identity-focused detections, not the cloud app alert stream required by the scenario.
- ✗
Enable the Microsoft 365 data connector in Microsoft Sentinel.
Why it's wrong here
The Microsoft 365 data connector in Microsoft Sentinel pulls raw auditing and activity logs from Exchange Online, SharePoint Online, Microsoft Teams, and other Office 365 workloads via the Office 365 Management Activity API. These are operational activity records rather than Defender for Cloud Apps security alerts. Even though Defender for Cloud Apps may internally consume some Office 365 audit data, this connector does not ingest MDCA-generated alerts or create incidents from those detections, so it is not the correct integration for the stated requirement.
- ✗
Create a playbook that triggers on Defender for Cloud Apps alerts and creates incidents in Sentinel.
Why it's wrong here
Using a playbook requires manual orchestration logic via Azure Logic Apps to bridge the two services, whereas the native Microsoft Sentinel connector automates this integration directly. This approach is tempting because playbooks are used for automated incident response actions, such as disabling a user in Microsoft Entra ID or blocking an IP address once an alert has already been processed.
- ✓
Enable the Microsoft Defender for Cloud Apps data connector in Microsoft Sentinel.
Why this is correct
The Microsoft Defender for Cloud Apps data connector is the native Microsoft Sentinel integration designed to ingest alerts from Defender for Cloud Apps, including impossible travel, activity from anonymous IP addresses, and suspicious cloud application usage. It uses the MDCA API to automatically pull these alerts and create corresponding incidents in Sentinel without requiring custom Logic Apps or playbook orchestration. Enabling this connector is the correct configuration to satisfy the requirement of having Defender for Cloud Apps alerts appear as Sentinel incidents.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Defender for Cloud Apps. You need to ensure that alerts from Defender for Cloud Apps are forwarded to Microsoft Sentinel. Which connector should you use in Sentinel?
easy- A.Windows Security Events via AMA connector
- ✓ B.Microsoft Defender for Cloud Apps connector
- C.Microsoft 365 Defender connector
- D.Azure Activity connector
Why B: The Microsoft Defender for Cloud Apps connector in Microsoft Sentinel is specifically designed to ingest alerts and logs from Defender for Cloud Apps, including anomaly detection, policy violations, and threat intelligence alerts. This connector uses the Microsoft Graph API to pull data directly from the Defender for Cloud Apps service, ensuring that all relevant security alerts are forwarded to Sentinel for centralized monitoring and incident response.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.