Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You receive an alert from Defender for Cloud indicating that a virtual machine has a high severity vulnerability (CVE-2023-XXXX). You need to create an incident in Microsoft Sentinel and trigger a playbook to remediate the vulnerability. However, the incident is not being created automatically. What is the most likely cause?

⚠ Common exam trap

Many candidates assume Defender for Cloud alerts automatically create incidents in Sentinel without needing a connector, or they confuse the connector with an analytics rule, thinking a custom rule is required to match severity thresholds.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Microsoft Defender for Cloud connector in Microsoft Sentinel is not enabled or misconfigured

The Microsoft Defender for Cloud connector in Microsoft Sentinel is the bridge that forwards security alerts from Defender for Cloud to Sentinel. If this connector is not enabled or is misconfigured, Defender for Cloud alerts—including vulnerability alerts for VMs—will never reach Sentinel, so no incident can be created automatically. Without the connector, the data source is disconnected, and Sentinel has no trigger to generate an incident or invoke a playbook.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The Microsoft Defender for Cloud connector in Microsoft Sentinel is not enabled or misconfigured

    Why this is correct

    The Microsoft Defender for Cloud connector is the data ingestion pipeline that brings security alerts from Defender for Cloud into Microsoft Sentinel. If this connector is disabled, not connected to the correct subscription, or has misconfigured diagnostic settings, no Defender for Cloud alerts reach the Sentinel workspace, so no incidents can be generated from them. Without this connector enabled, all other components—analytics rules, automation, and playbooks—have no alert data to act upon.

  • ✗

    An analytics rule with a matching severity threshold has not been created

    Why it's wrong here

    In Microsoft Sentinel, incidents from Microsoft Defender for Cloud alerts are created automatically by the connector itself, not by separate analytics rules. Analytics rules are used to generate alerts and incidents from raw data sources such as logs, and a rule with a matching severity threshold would not be required for Defender for Cloud alert ingestion. Even if you create such a rule, it would not affect the existing incident creation path from Defender for Cloud alerts.

  • ✗

    The free trial of Microsoft Sentinel has expired

    Why it's wrong here

    The expiration of a Microsoft Sentinel free trial affects the workspace's licensing status and may eventually disable the service, but it does not alter the connector's configuration or the data ingestion pipeline. Existing connectors, including the Defender for Cloud connector, remain enabled and continue to stream alerts until the workspace is actually removed or the connector is manually deleted. Therefore, a lapsed trial would not specifically prevent incidents from Defender for Cloud alerts while other incident sources still work.

  • ✗

    The playbook does not have the correct permissions on the target VM

    Why it's wrong here

    Playbook permissions are relevant only to the automation step that executes after an incident is created, such as a response action on a virtual machine. If a playbook lacks the necessary permissions on the target VM, the remediation action will fail, but the incident creation from a Defender for Cloud alert is unaffected. Incident generation occurs during alert ingestion and processing, well before any playbook is invoked, so this misconfiguration cannot explain the absence of incidents.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.