SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Cloud Apps. You need to ensure that alerts from Defender for Cloud Apps are forwarded to Microsoft Sentinel. Which connector should you use in Sentinel?
⚠ Common exam trap
Candidates often confuse the Microsoft 365 Defender connector as a catch-all for all Microsoft security alerts, but it does not include Defender for Cloud Apps alerts, which require their own dedicated connector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Cloud Apps connector
The Microsoft Defender for Cloud Apps connector in Microsoft Sentinel is specifically designed to ingest alerts and logs from Defender for Cloud Apps, including anomaly detection, policy violations, and threat intelligence alerts. This connector uses the Microsoft Graph API to pull data directly from the Defender for Cloud Apps service, ensuring that all relevant security alerts are forwarded to Sentinel for centralized monitoring and incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Windows Security Events via AMA connector
Why it's wrong here
The Windows Security Events via AMA connector is designed to collect Windows Event Log entries, such as security audit logs, from Azure, AWS, or on-premises virtual machines using the Azure Monitor Agent. It is a host-based log source that captures operating system and application events, but it does not ingest alert data from Microsoft Defender for Cloud Apps. Therefore, it cannot provide any Defender for Cloud Apps alert content.
- ✓
Microsoft Defender for Cloud Apps connector
Why this is correct
This is the dedicated Microsoft Sentinel data connector for ingesting alerts and anomalies from Microsoft Defender for Cloud Apps, including policy violations, activity anomalies, and threat detection from cloud applications. It uses the Defender for Cloud Apps API to pull alerts into Log Analytics when enabled. Choosing this connector ensures that all cloud app security alerts are available for investigation and for use in analytics rules.
- ✗
Microsoft 365 Defender connector
Why it's wrong here
The Microsoft 365 Defender connector imports incidents and alerts from the unified Microsoft 365 Defender portal, which consolidates signals from Defender for Endpoint, Office 365, Identity, and sometimes Cloud Apps. However, this connector does not directly bring in Defender for Cloud Apps alerts as a dedicated stream; alerts from Cloud Apps may be absent if they are not correlated into an M365 Defender incident. To ensure complete Cloud Apps alert ingestion, you must use the dedicated Defender for Cloud Apps connector.
- ✗
Azure Activity connector
Why it's wrong here
The Azure Activity connector ingests subscription-level management plane logs from Azure Resource Manager, such as resource provisioning, role assignment, and service health events. It does not ingest user activity or alert data from third-party SaaS or cloud app services. Defender for Cloud Apps alerts are generated from user behavior in cloud applications, not from the Azure control plane, so this connector is irrelevant to the scenario.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.