Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Identity (MDI) to monitor on-premises Active Directory. You want to forward MDI alerts to Microsoft Sentinel. What should you configure?

⚠ Common exam trap

Test-takers frequently confuse the Microsoft Defender for Identity connector with the Microsoft 365 Defender connector, assuming the unified portal connector is the correct way to forward MDI alerts, but the exam expects the specific product-named connector for direct integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Identity connector

Microsoft Defender for Identity (MDI) alerts are forwarded to Microsoft Sentinel by configuring the Microsoft Defender for Identity data connector. This connector ingests MDI security alerts, such as suspicious Kerberos activity or lateral movement attempts, directly into Sentinel for advanced correlation and incident response. The connector uses the Microsoft Graph Security API to pull alerts from the MDI service, enabling seamless integration without additional agents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft 365 Defender connector

    Why it's wrong here

    The Microsoft 365 Defender connector (now Microsoft Defender XDR) ingests unified incidents and correlated alerts from across the defender suite, but it does not export raw Microsoft Defender for Identity alerts directly. When you enable this connector, you receive high-level incidents that may reference identity threats, but the standalone MDI alert details are not populated into Sentinel through this path, so it cannot serve as the required connector for MDI alert ingestion.

  • ✗

    Azure Advanced Threat Protection connector

    Why it's wrong here

    Azure Advanced Threat Protection (ATP) was the predecessor to Microsoft Defender for Identity, and its Sentinel connector was deprecated when the service was rebranded and replaced. Although older deployments might have used the Azure ATP connector to bring in legacy identity alerts, Microsoft no longer supports it, and the current, supported integration is the dedicated Microsoft Defender for Identity connector; selecting an obsolete connector would not work in a modern deployment.

  • ✗

    Microsoft Defender for Cloud Apps connector

    Why it's wrong here

    The Microsoft Defender for Cloud Apps connector is designed to bring in alerts and activities from the cloud application security broker, such as shadow IT discovery, cloud app anomalies, and policy violations for SaaS applications. It does not provide any mechanism to retrieve on-premises or hybrid identity alerts generated by Microsoft Defender for Identity, which focuses on attack techniques like pass-the-hash, golden ticket, and domain controller reconnaissance, so it is not the correct connector for this need.

  • ✓

    Microsoft Defender for Identity connector

    Why this is correct

    The Microsoft Defender for Identity connector is the direct and supported data connector in Sentinel for ingesting identity security alerts from Microsoft Defender for Identity. It authenticates to the MDI API and pulls raw alerts—including suspected lateral movement, account enumeration, and domain controller compromise—into the SecurityAlert table with the provider name 'MicrosoftDefenderForIdentity', making it the correct choice for this organization.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.