Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender XDR and Microsoft Sentinel. You need to ensure that when a user reports a phishing email in Microsoft 365 Defender, the incident in Microsoft Sentinel is automatically updated with the user's comments. Which THREE components are required?

⚠ Common exam trap

A common mix-up: candidates think a logic app triggered directly by the alert (Option A) is sufficient, but the required flow must use a Sentinel playbook triggered by an automation rule to ensure the incident update occurs within Sentinel's context.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Microsoft 365 Defender data connector in Microsoft Sentinel.

The Microsoft 365 Defender data connector in Microsoft Sentinel is required because it ingests alerts and incidents from Microsoft 365 Defender into Sentinel. Without this connector, the phishing email report from Microsoft 365 Defender would not create an incident in Sentinel, making it impossible to automatically update that incident with user comments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A logic app in Azure that is triggered by the Microsoft 365 Defender alert.

    Why it's wrong here

    A logic app that is triggered directly by a Microsoft 365 Defender alert is not the correct component because it bypasses Microsoft Sentinel's incident pipeline. While a playbook is technically an Azure Logic App, the required architecture uses an automation rule to invoke the playbook only after Sentinel receives and creates an incident. Directly triggering a logic app from the alert would leave the incident in Sentinel unmodified, so it does not satisfy the requirement to update the incident with comments.

  • ✓

    The Microsoft 365 Defender data connector in Microsoft Sentinel.

    Why this is correct

    The Microsoft 365 Defender data connector in Microsoft Sentinel is essential because it ingests alerts and raw events from Defender XDR into the Log Analytics workspace. This connector creates the SecurityAlert and SecurityIncident tables that Sentinel uses to generate incidents, and without it, no Microsoft 365 Defender alert would ever reach Sentinel to trigger any automation. This is why it is the correct component to include, as it is the foundational source of the incident data.

  • ✗

    The Microsoft Entra ID data connector in Microsoft Sentinel.

    Why it's wrong here

    The Microsoft Entra ID data connector is incorrect because it ingests identity-based logs such as sign-in logs and audit logs, not Microsoft 365 Defender alerts. These logs may contain identity incidents, but they do not provide the Defender XDR alert data that is the basis for the incident being updated. Including this connector would not fulfill the requirement to act on Defender alerts, and it would also duplicate the identity signals already available through the Microsoft 365 Defender connector.

  • ✓

    A playbook in Microsoft Sentinel that updates the incident with the user's comments.

    Why this is correct

    A playbook in Microsoft Sentinel that updates the incident with the user's comments is a necessary component because it is the executable workflow that performs the actual update action. This playbook, built on Azure Logic Apps or Power Automate, runs actions such as 'Add a comment to incident' or invokes the SecurityIncident API to modify the incident record. Without this playbook, there would be no mechanism to write the user's comments back to the incident after the alert is processed.

  • ✓

    An automation rule in Microsoft Sentinel that triggers the playbook when an incident is created from a Microsoft 365 Defender alert.

    Why this is correct

    An automation rule in Microsoft Sentinel is required to trigger the playbook when an incident is created from a Microsoft 365 Defender alert. This rule defines the trigger conditions (e.g., provider equals Microsoft 365 Defender, or specific alert severity) and specifies the playbook to run, acting as the orchestration layer between the incoming alert data and the remediation action. Without an automation rule, the playbook would be inert, even if the data connector delivers the alert to Sentinel.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.