Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Cloud Apps. You need to ensure that alerts from Defender for Cloud Apps are forwarded to Microsoft Sentinel. Which connector should you use in Sentinel?

⚠ Common exam trap

Candidates often confuse the Microsoft 365 Defender connector as a catch-all for all Microsoft security alerts, but it does not include Defender for Cloud Apps alerts, which require their own dedicated connector.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Cloud Apps connector

The Microsoft Defender for Cloud Apps connector in Microsoft Sentinel is specifically designed to ingest alerts and logs from Defender for Cloud Apps, including anomaly detection, policy violations, and threat intelligence alerts. This connector uses the Microsoft Graph API to pull data directly from the Defender for Cloud Apps service, ensuring that all relevant security alerts are forwarded to Sentinel for centralized monitoring and incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Windows Security Events via AMA connector

    Why it's wrong here

    The Windows Security Events via AMA connector is designed to collect Windows Event Log entries, such as security audit logs, from Azure, AWS, or on-premises virtual machines using the Azure Monitor Agent. It is a host-based log source that captures operating system and application events, but it does not ingest alert data from Microsoft Defender for Cloud Apps. Therefore, it cannot provide any Defender for Cloud Apps alert content.

  • ✓

    Microsoft Defender for Cloud Apps connector

    Why this is correct

    This is the dedicated Microsoft Sentinel data connector for ingesting alerts and anomalies from Microsoft Defender for Cloud Apps, including policy violations, activity anomalies, and threat detection from cloud applications. It uses the Defender for Cloud Apps API to pull alerts into Log Analytics when enabled. Choosing this connector ensures that all cloud app security alerts are available for investigation and for use in analytics rules.

  • ✗

    Microsoft 365 Defender connector

    Why it's wrong here

    The Microsoft 365 Defender connector imports incidents and alerts from the unified Microsoft 365 Defender portal, which consolidates signals from Defender for Endpoint, Office 365, Identity, and sometimes Cloud Apps. However, this connector does not directly bring in Defender for Cloud Apps alerts as a dedicated stream; alerts from Cloud Apps may be absent if they are not correlated into an M365 Defender incident. To ensure complete Cloud Apps alert ingestion, you must use the dedicated Defender for Cloud Apps connector.

  • ✗

    Azure Activity connector

    Why it's wrong here

    The Azure Activity connector ingests subscription-level management plane logs from Azure Resource Manager, such as resource provisioning, role assignment, and service health events. It does not ingest user activity or alert data from third-party SaaS or cloud app services. Defender for Cloud Apps alerts are generated from user behavior in cloud applications, not from the Azure control plane, so this connector is irrelevant to the scenario.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.