Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Office 365. You need to ensure that suspicious email messages are automatically moved to quarantine and an incident is raised in Microsoft Sentinel. What should you configure?

⚠ Common exam trap

Many candidates confuse the purpose of data connectors—thinking any 'Defender' connector (e.g., Defender for Cloud or Defender for Endpoint) can ingest email security events, when in fact only the specific Office 365 connector handles email quarantine and incident generation for Defender for Office 365.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the Microsoft Defender for Office 365 data connector in Sentinel.

The Microsoft Defender for Office 365 data connector in Microsoft Sentinel ingests email-related alerts and events (e.g., phishing, malware, spam) from Defender for Office 365. When you configure automated investigation and response (AIR) policies in Defender for Office 365 to move suspicious emails to quarantine, and enable the connector in Sentinel, those quarantine actions trigger corresponding incidents in Sentinel. This integration ensures that email threats are both remediated (quarantined) and tracked as security incidents for further analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the Microsoft Defender for Office 365 data connector in Sentinel.

    Why this is correct

    The Microsoft Defender for Office 365 data connector in Sentinel is the appropriate choice because it directly ingests rich Office 365 security signals, including alerts for phishing, malware, malicious URLs, and user-reported email threats, as well as unified incidents. This connector enables you to automatically collect these alerts and correlate them with other analytics in Sentinel, providing complete visibility into email, Teams, and compliance-related threats. No other connector provides native, purpose-built ingestion of Office 365 protection data.

  • ✗

    Configure the Microsoft Defender for Cloud data connector in Sentinel.

    Why it's wrong here

    The Microsoft Defender for Cloud data connector is designed to bring in security alerts from cloud workload protections, such as Defender for Servers, Defender for App Service, Defender for Storage, and Defender for SQL, along with posture management findings. It does not ingest alerts or incidents related to Microsoft 365 email and collaboration platforms like Exchange Online, SharePoint Online, or Teams. Therefore, configuring this connector would not provide the Office 365 email protection alerts that you need, making it an incorrect answer for this scenario.

  • ✗

    Use the Microsoft Defender for Identity data connector.

    Why it's wrong here

    The Microsoft Defender for Identity data connector pulls alerts from Microsoft Entra ID and domain controller telemetry, such as account compromise, lateral movement, and privilege escalation incidents, but it does not provide email-focused threat detection. While identity threats can sometimes correlate with phishing, the connector's scope is strictly identity and authentication events, not inbound email message analysis or Office 365 alerting. Since the organization's requirement centers on Defender for Office 365 alerts and incidents, this connector is not a valid substitute.

  • ✗

    Enable the Microsoft Defender for Endpoint data connector.

    Why it's wrong here

    The Microsoft Defender for Endpoint data connector ingests endpoint detection and response (EDR) alerts generated from devices like Windows, Linux, and macOS, covering malware execution, suspicious processes, and attacker techniques at the host level. It is not designed to receive Office 365 email protection alerts, which are generated by Exchange Online Protection and Defender for Office 365 policies. This connector would leave the Office 365 workload unprotected in Sentinel, so it is an incorrect option for your requirement.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.