SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender XDR. You need to ensure that alerts from Microsoft Defender for Identity are automatically correlated with alerts from Microsoft Defender for Endpoint in the unified incidents queue. What should you verify?
⚠ Common exam trap
Test-takers frequently confuse the need for a SIEM integration (like Microsoft Sentinel) or additional workload licensing (like Defender for Office 365) with the native, built-in correlation capability of Defender XDR, which is controlled by a single toggle in the settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR incident correlation is enabled
Microsoft Defender XDR incident correlation is the feature that automatically aggregates alerts from different Microsoft Defender workloads—including Defender for Identity and Defender for Endpoint—into a single unified incident. When this setting is enabled, the correlation engine analyzes alert telemetry and entities (such as user accounts, devices, and IP addresses) to merge related alerts, reducing alert fatigue and providing a consolidated view. Without this setting enabled, alerts from different workloads remain isolated and are not automatically correlated in the unified incidents queue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Office 365 is enabled
Why it's wrong here
Enabling Microsoft Defender for Office 365 only activates email and collaboration protection for workloads such as Exchange Online and SharePoint. While alerts generated by MDO are ingested into the Microsoft Defender XDR incident pipeline, this workload alone does not enable the platform-wide correlation engine. Cross-workload incident correlation requires the centralized XDR correlation setting, not merely activation of an individual workload sensor.
- ✓
Microsoft Defender XDR incident correlation is enabled
Why this is correct
The Microsoft Defender XDR incident correlation setting is the core aggregation mechanism that fuses alerts from Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps into a single incident. It leverages the entity graph and attack-story logic to link related alerts based on user, device, and process relationships. Enabling this switch is what allows alerts to be merged into a unified, cross-workload incident rather than appearing as disjointed alerts.
- ✗
Microsoft Sentinel is connected to Microsoft Defender XDR
Why it's wrong here
Connecting Microsoft Sentinel to Microsoft Defender XDR creates a SIEM integration that streams incidents and alerts into Sentinel for broader security operations and analytics. This integration is unidirectional for ingestion and does not modify how Defender XDR internally correlates alerts or forms incidents. Correlation within Defender XDR is determined solely by its own incident-correlation engine, independent of any external SIEM connectivity.
- ✗
Custom detection rules are created in Microsoft 365 Defender
Why it's wrong here
Custom detection rules in Microsoft 365 Defender are KQL-based queries that generate standalone alerts when certain conditions are matched. These alerts are then fed into the existing incident pipeline, but they do not activate or influence the correlation logic that groups alerts into incidents. Incident correlation remains governed by the platform's built-in Microsoft Defender XDR correlation setting, so creating custom rules does not enable or enhance that capability.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.