SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel and Microsoft Defender for Office 365. You have configured incident creation from Microsoft Defender for Office 365 alerts in Microsoft Sentinel. However, you notice that some alerts are not creating incidents. Which step should you take to troubleshoot this issue?
⚠ Common exam trap
It's easy for candidates to assume the issue is with data ingestion (Option D) or alert generation (Option B), but the actual cause is a misconfigured severity threshold within the analytics rule that silently filters out lower-severity alerts before they can become incidents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Examine the analytics rule that creates incidents from Microsoft Defender for Office 365 alerts and verify the severity threshold.
The analytics rule that maps Microsoft Defender for Office 365 alerts to incidents in Microsoft Sentinel includes a severity threshold filter. If the rule is configured to only create incidents for alerts with a severity of 'High' or 'Medium', alerts with 'Low' severity or 'Informational' will be silently dropped and not generate incidents. Verifying and adjusting this threshold directly addresses the root cause of missing incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Examine the analytics rule that creates incidents from Microsoft Defender for Office 365 alerts and verify the severity threshold.
Why this is correct
The correct action is to examine the analytics rule that creates incidents from Microsoft Defender for Office 365 alerts, because Microsoft Sentinel does not automatically create incidents from every raw alert. Analytics rules use KQL queries to match incoming alerts and apply conditions, and if the rule's severity threshold (e.g., only Medium and higher) is too high, alerts with lower severity won't trigger an incident. Verifying the rule's query, alert grouping, and severity filter directly addresses the symptom of users receiving Microsoft 365 Defender alerts while Sentinel incidents are missing.
- ✗
Check the Microsoft 365 Defender portal to confirm that the alerts are being generated.
Why it's wrong here
Checking the Microsoft 365 Defender portal only confirms that alerts were generated and delivered to the security stack, but it does not validate the Sentinel-to-analytics-rule processing pipeline. Even if alerts exist in Defender, they can be filtered out by the analytics rule's KQL condition, suppressed by an incident creation setting, or fail to include the expected severity level. Therefore, this action is insufficient because the portal does not expose whether Sentinel's rule has ingested and matched those alerts.
- ✗
Review the Microsoft Sentinel workbooks for any visualization errors.
Why it's wrong here
Reviewing Microsoft Sentinel workbooks is unrelated to incident creation mechanics; workbooks are visualization layers that render data from existing tables and queries, not components that generate incidents. Even if a workbook appears broken or empty, it has no bearing on whether an analytics rule's severity threshold or trigger condition is satisfied. Consequently, this action only investigates reporting integrity, which cannot diagnose missing incidents from Microsoft Defender for Office 365 alerts.
- ✗
Verify that the Microsoft Defender for Office 365 data connector in Microsoft Sentinel is connected and data is ingested.
Why it's wrong here
Verifying that the Microsoft Defender for Office 365 data connector is connected and ingesting data is a prerequisite but not the root cause here, because the connector's role ends at landing raw alerts into Sentinel tables. Once alerts are ingested, the analytics rule—not the connector—determines which alerts become incidents. If the connector is healthy and data flows, the problem remains that the analytic rule may be excluding alerts due to severity threshold or other filters, so this action alone won't explain or fix the missing incidents.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.