SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You are responsible for managing the security operations environment. Recently, the SOC team reported that incidents from Microsoft Defender for Endpoint are not appearing in Microsoft Sentinel. You have already configured the data connector for Microsoft Defender XDR and verified that logs are flowing into the 'SecurityAlert' table. However, incidents are not being created in Sentinel. What should you do?
⚠ Common exam trap
SC-200 often tests the distinction between data ingestion and incident creation, causing candidates to focus on analytics rules or other connectors when the missing step is enabling the incident creation toggle in the Defender XDR connector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable 'Create incidents from Microsoft 365 Defender' in the Microsoft Defender XDR data connector.
Enabling 'Create incidents from Microsoft 365 Defender' in the Microsoft Defender XDR data connector (A) is the correct action. This setting allows Microsoft Sentinel to automatically create incidents from alerts generated by Microsoft Defender XDR, including those from Defender for Endpoint. Even though alerts are flowing into the SecurityAlert table, incident creation requires this specific toggle to be enabled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable 'Create incidents from Microsoft 365 Defender' in the Microsoft Defender XDR data connector.
Why this is correct
Enabling 'Create incidents from Microsoft 365 Defender' on the Microsoft Defender XDR data connector is the designated method for ingesting already-correlated incidents into Microsoft Sentinel. This toggle allows the connector to pull Defender XDR incidents directly from the Microsoft Graph Security API, ensuring Sentinel receives the full incident with its related alerts, entities, and attack story. Without this setting, the connector would only ingest raw alerts, leaving you to rebuild the correlation that Defender XDR already performed, which defeats the purpose of unified incident management.
- ✗
Create an analytics rule that queries the SecurityAlert table and generates incidents.
Why it's wrong here
This approach is incorrect because analytics rules in Microsoft Sentinel generate incidents from data stored in tables like SecurityAlert, SecurityEvent, or custom tables, and they apply detection logic to raw or normalized telemetry. Defender XDR incidents are not written to the SecurityAlert table as individual incidents; they are created by Microsoft 365 Defender's correlation engine and delivered through the connector's incident ingestion pipeline. Creating an analytics rule on SecurityAlert would only generate separate Sentinel incidents from individual alerts, leading to duplication and loss of the multi-alert context that Defender XDR provides.
- ✗
Verify the Azure Sentinel solution is installed and enable the streaming of incidents.
Why it's wrong here
This option misinterprets the role of an installed solution in Microsoft Sentinel. The Azure Sentinel/Microsoft Sentinel solution provides content such as data connectors, workbooks, and analytics rule templates, but it does not automatically stream incidents from Defender XDR. Additionally, streaming in Sentinel typically refers to the ingestion of logs via settings like diagnostic settings or the AMA, not to the creation of incidents. The actual mechanism for incident ingestion from Defender XDR is the explicit 'Create incidents from Microsoft 365 Defender' toggle within the Microsoft Defender XDR data connector, not a generic solution-level setting.
- ✗
Configure the Microsoft Defender for Endpoint data connector.
Why it's wrong here
Configuring the Microsoft Defender for Endpoint (MDE) data connector alone is insufficient because that connector is designed to ingest only alert telemetry from MDE, not incidents aggregated by Microsoft 365 Defender. Defender XDR incidents are assembled by the XDR correlation engine and can contain alerts from multiple Defender services (Endpoint, Identity, Office 365, Defender for Cloud Apps). To bring those incidents into Sentinel, you must use the Microsoft Defender XDR data connector and enable its incident creation toggle; the MDE connector would merely populate the SecurityAlert table with individual endpoint alerts, not the correlated incident.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Sentinel and Microsoft Defender XDR. The security team wants to automatically create an incident in Microsoft Sentinel when a Microsoft Defender for Endpoint alert is triggered. What should you configure?
easy- ✓ A.Enable the Microsoft Defender XDR connector in Microsoft Sentinel and select the incident creation settings.
- B.Set up a Logic App custom connector to poll Defender alerts.
- C.Configure the Security Events connector to forward Defender alerts.
- D.Create analytics rules in Microsoft Sentinel for each Defender alert type.
Why A: The Microsoft Defender XDR connector in Microsoft Sentinel is specifically designed to ingest alerts and incidents from Microsoft Defender for Endpoint and other Defender products. By enabling this connector and configuring its incident creation settings, Sentinel automatically creates incidents when Defender for Endpoint alerts are triggered, without requiring custom logic or manual polling.
Variation 2. Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You want to ensure that incidents generated in Microsoft 365 Defender are automatically synchronized to Microsoft Sentinel. What should you configure?
easy- A.Set up an automation rule to import incidents
- B.Configure the Microsoft Sentinel connector in Microsoft Defender XDR
- C.Create an analytics rule to query Defender XDR data
- ✓ D.Enable the Microsoft Defender XDR data connector in Microsoft Sentinel
Why D: The Microsoft Defender XDR data connector in Microsoft Sentinel is specifically designed to synchronize incidents from Microsoft 365 Defender into Sentinel. When enabled, this connector uses the Microsoft Graph Security API to ingest incidents, alerts, and evidence, ensuring automatic and bidirectional synchronization without requiring additional automation rules or analytics queries.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.