Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender XDR. You need to ensure that alerts from Microsoft Defender for Identity are automatically correlated with alerts from Microsoft Defender for Endpoint in the unified incidents queue. What should you verify?

⚠ Common exam trap

Test-takers frequently confuse the need for a SIEM integration (like Microsoft Sentinel) or additional workload licensing (like Defender for Office 365) with the native, built-in correlation capability of Defender XDR, which is controlled by a single toggle in the settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender XDR incident correlation is enabled

Microsoft Defender XDR incident correlation is the feature that automatically aggregates alerts from different Microsoft Defender workloads—including Defender for Identity and Defender for Endpoint—into a single unified incident. When this setting is enabled, the correlation engine analyzes alert telemetry and entities (such as user accounts, devices, and IP addresses) to merge related alerts, reducing alert fatigue and providing a consolidated view. Without this setting enabled, alerts from different workloads remain isolated and are not automatically correlated in the unified incidents queue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Office 365 is enabled

    Why it's wrong here

    Enabling Microsoft Defender for Office 365 only activates email and collaboration protection for workloads such as Exchange Online and SharePoint. While alerts generated by MDO are ingested into the Microsoft Defender XDR incident pipeline, this workload alone does not enable the platform-wide correlation engine. Cross-workload incident correlation requires the centralized XDR correlation setting, not merely activation of an individual workload sensor.

  • ✓

    Microsoft Defender XDR incident correlation is enabled

    Why this is correct

    The Microsoft Defender XDR incident correlation setting is the core aggregation mechanism that fuses alerts from Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps into a single incident. It leverages the entity graph and attack-story logic to link related alerts based on user, device, and process relationships. Enabling this switch is what allows alerts to be merged into a unified, cross-workload incident rather than appearing as disjointed alerts.

  • ✗

    Microsoft Sentinel is connected to Microsoft Defender XDR

    Why it's wrong here

    Connecting Microsoft Sentinel to Microsoft Defender XDR creates a SIEM integration that streams incidents and alerts into Sentinel for broader security operations and analytics. This integration is unidirectional for ingestion and does not modify how Defender XDR internally correlates alerts or forms incidents. Correlation within Defender XDR is determined solely by its own incident-correlation engine, independent of any external SIEM connectivity.

  • ✗

    Custom detection rules are created in Microsoft 365 Defender

    Why it's wrong here

    Custom detection rules in Microsoft 365 Defender are KQL-based queries that generate standalone alerts when certain conditions are matched. These alerts are then fed into the existing incident pipeline, but they do not activate or influence the correlation logic that groups alerts into incidents. Incident correlation remains governed by the platform's built-in Microsoft Defender XDR correlation setting, so creating custom rules does not enable or enhance that capability.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.