SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Purview Data Loss Prevention (DLP) policies. You need to investigate an incident where sensitive data was shared externally. You want to view the details in Microsoft Sentinel. What should you ensure is configured?
⚠ Common exam trap
It's easy for candidates to assume enabling the unified audit log (Option D) is sufficient for Sentinel to receive DLP alerts, but they overlook that the Microsoft 365 data connector must be specifically configured to collect DLP events, as the connector acts as the bridge between the audit log and Sentinel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Microsoft 365 data connector in Microsoft Sentinel is enabled and configured to collect DLP alerts.
Microsoft Sentinel's Microsoft 365 data connector ingests unified audit logs from Microsoft Purview, including DLP alerts. When this connector is enabled and configured to collect DLP alerts, Sentinel can receive and surface the incident details, allowing investigation of externally shared sensitive data. Without this connector, DLP events remain in the Purview compliance portal and are not forwarded to Sentinel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The Microsoft 365 data connector in Microsoft Sentinel is enabled and configured to collect DLP alerts.
Why this is correct
This connector is the explicit, required data ingestion path between Microsoft Purview DLP and Microsoft Sentinel. It calls the Office 365 Management API to pull DLP alert records and writes them into the SecurityAlert table, which is what Sentinel analytics rules actually query. Without this connector enabled and configured, no DLP alert—regardless of policy mode or audit logging—will appear in Sentinel. Therefore, it is the only condition that directly determines whether DLP alerts are ingested.
- ✗
The SharePoint site is configured for external sharing.
Why it's wrong here
Enabling external sharing on a SharePoint site controls whether outside users can access content, but it has no bearing on how Sentinel ingests DLP alerts. DLP policy evaluation occurs independently of site sharing settings; even a site with limited sharing generates DLP alerts when sensitive content is matched. External sharing also does not affect the Office 365 Management API's ability to stream DLP alert telemetry. Thus, this setting is irrelevant to the failed data ingestion scenario.
- ✗
The DLP policy must be set to 'Audit only' mode.
Why it's wrong here
Setting the DLP policy to 'Audit only' mode affects the remediation action taken after a policy match but does not influence alert generation or ingestion. In fact, both audit-only and enforce modes generate DLP alerts, and those alerts are candidates for Sentinel ingestion. If the Microsoft 365 data connector is disabled, none of these alerts will be collected regardless of the policy's mode. Therefore, audit-only is not a prerequisite; the connector is the actual requirement.
- ✗
The unified audit log is enabled and the DLP events are being generated.
Why it's wrong here
While enabling the unified audit log is a prerequisite for DLP events to be recorded, the mere presence of those events in the audit log does not automatically forward them to Sentinel. The Microsoft 365 data connector is the component that specifically pulls DLP alerts from the Office 365 Management API into Sentinel's SecurityAlert table. If the connector is disabled, the audit log may contain the events, but they will never be ingested into Sentinel for detection and response. Thus, this condition is necessary but not sufficient, as the connector is still required.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.