SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Office 365 and Microsoft Sentinel. You discover that phishing emails are bypassing Defender for Office 365 and being reported by users. You need to ensure that user-reported emails are automatically analyzed and incidents are created in Sentinel for high-confidence phishing. What should you configure?
⚠ Common exam trap
Watch out — candidates often assume a custom connector or mail flow rule is necessary for ingestion, overlooking that the built-in Defender for Office 365 user-reported messages feature, when combined with the Microsoft Defender XDR connector, provides a fully automated and integrated solution for high-confidence phishing incident creation in Sentinel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the 'User reported messages' feature in Defender for Office 365 and ensure the Microsoft Defender XDR connector is enabled in Sentinel.
Enabling the 'User reported messages' feature in Defender for Office 365 allows user-reported phishing emails to be automatically submitted to Microsoft for analysis. When the Microsoft Defender XDR connector is enabled in Sentinel, high-confidence phishing verdicts from this analysis are ingested as incidents, creating a seamless automated pipeline without custom infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set up a custom connector using Microsoft Graph API to ingest user-reported messages into Sentinel.
Why it's wrong here
While a custom Microsoft Graph API connector could ingest user-reported messages into Sentinel, it would not automatically analyse them for high-confidence phishing or trigger incident creation without additional custom logic and playbooks. The scenario requires built-in automated analysis and incident generation, which is provided by the native integration between Defender for Office 365 and Sentinel via the Microsoft 365 Defender connector. This option is tempting because Graph API is a flexible method for ingesting arbitrary email data into Sentinel, and would be correct if the requirement were only to collect raw messages without automated phishing classification.
- ✗
Use the Microsoft 365 Defender portal to create a submission rule for user-reported messages.
Why it's wrong here
The Microsoft 365 Defender submission portal is designed for admin-driven message analysis and remediation, not for automated incident generation. Creating a submission rule only forwards messages to Microsoft for scanning and displays results in the Submissions view; it does not integrate with Microsoft Sentinel to create alerts or incidents. Any response to a submitted message would require manual triage by a security analyst, so this fails the requirement for automated analysis and incident creation.
- ✗
Configure a mail flow rule to forward user-reported messages to a dedicated mailbox monitored by Sentinel.
Why it's wrong here
A mail flow rule that forwards user-reported messages to a dedicated mailbox simply collects raw email data in a target location. While Sentinel could monitor that mailbox via a connector, it would still need custom parsing logic and playbooks to classify the email and generate an incident, and there is no built-in high-confidence phishing analysis. This approach lacks the native threat intelligence and automated investigation capabilities that the Defender for Office 365 integration provides.
- ✓
Enable the 'User reported messages' feature in Defender for Office 365 and ensure the Microsoft Defender XDR connector is enabled in Sentinel.
Why this is correct
Enabling the 'User reported messages' feature in Defender for Office 365 ensures that user-reported emails are automatically submitted for analysis by Microsoft's threat intelligence systems, including detonation and reputation checks. When the Microsoft Defender XDR connector is enabled in Microsoft Sentinel, the resulting alerts and incidents—such as high-confidence phishing verdicts—are streamed into Sentinel automatically, creating security incidents without manual intervention. This native integration is the correct method to meet the requirement for automated analysis and incident creation.
Go deeper
Related to this question
About these practice questions
One of 673 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.