Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender XDR. You need to ensure that all cloud app alerts are forwarded to Microsoft Sentinel for correlation. What should you configure?

⚠ Common exam trap

It's easy for candidates to confuse the purpose of data connectors for different Microsoft Defender products, mistakenly selecting the Defender for Endpoint connector when the question specifically targets cloud app alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In Microsoft Sentinel, enable the data connector for Microsoft Defender for Cloud Apps.

The Microsoft Defender for Cloud Apps data connector in Microsoft Sentinel is specifically designed to ingest alerts and cloud discovery logs from Defender for Cloud Apps. Enabling this connector ensures that all cloud app alerts are automatically forwarded to Sentinel for correlation without requiring custom API queries or external export pipelines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an analytics rule in Sentinel that queries Defender for Cloud Apps API.

    Why it's wrong here

    An analytics rule in Microsoft Sentinel is designed to generate alerts by running KQL queries over data that is already resident in its Log Analytics workspace. It does not act as an import mechanism, so it cannot pull historical or live alerts from the Defender for Cloud Apps API. You would have to build a separate custom collector to fetch API data, which duplicates functionality that the native data connector already provides without any development effort.

  • ✗

    Configure Microsoft Defender for Cloud Apps to export alerts to Azure Event Hubs.

    Why it's wrong here

    Exporting Defender for Cloud Apps alerts to Azure Event Hubs requires configuring diagnostic settings, then creating a separate Sentinel data connector or Function App to consume that stream into Log Analytics. While this architectural pattern can work for custom pipelines, it is an indirect and unnecessarily complex approach for routine alert ingestion. The Defender for Cloud Apps data connector in Sentinel directly ingests alerts through the Microsoft Graph Security API, making it the simplest and officially supported method.

  • ✓

    In Microsoft Sentinel, enable the data connector for Microsoft Defender for Cloud Apps.

    Why this is correct

    Enabling the Defender for Cloud Apps data connector in Microsoft Sentinel establishes a native, one-click ingestion pipeline that automatically imports alerts and incidents from the cloud app security service into Log Analytics. This connector uses Microsoft Graph Security API to synchronize alert data, allowing security analysts to investigate cloud application threats alongside other signals in Sentinel. Once enabled, alerts become available in the SecurityAlert table, and you can then build analytics rules or workbooks on top of them.

  • ✗

    In Microsoft Sentinel, enable the data connector for Microsoft Defender for Endpoint.

    Why it's wrong here

    The Microsoft Defender for Endpoint data connector is specifically designed to ingest endpoint detection and response (EDR) alerts, device inventory, and related security events from managed endpoints. It has no integration with Defender for Cloud Apps, which generates alerts based on cloud application usage, OAuth app permissions, and anomalous user behavior in SaaS apps. Selecting this connector would bring in endpoint telemetry but would leave cloud app alerts entirely uncollected, so it does not satisfy the requirement to ingest Defender for Cloud Apps data.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.