Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You need to ensure that incidents created in Microsoft Defender XDR are automatically synchronized to Microsoft Sentinel with the least administrative effort. What should you configure?

⚠ Common exam trap

Candidates often confuse raw data ingestion (e.g., streaming raw logs from Defender for Endpoint) with incident synchronization, leading them to select Option C, when in fact incidents require the dedicated Microsoft Defender XDR data connector for automated, low-effort synchronization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the Microsoft Defender XDR data connector in Microsoft Sentinel.

The Microsoft Defender XDR data connector in Microsoft Sentinel provides a built-in, one-click integration that automatically synchronizes incidents from Microsoft Defender XDR to Microsoft Sentinel with no custom development required. This connector uses the Microsoft Graph Security API to ingest incidents, alerts, and evidence, ensuring seamless bidirectional synchronization with the least administrative effort.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a Logic App that uses the Microsoft Defender XDR API to fetch incidents and push them to Microsoft Sentinel.

    Why it's wrong here

    A Logic App would necessitate designing and maintaining a custom workflow that calls the Microsoft Defender XDR API, including authentication, pagination, error handling, and scheduled polling. This introduces extra infrastructure and latency compared to the native connector, and you would still need to manually transform the fetched incident data into the Microsoft Sentinel incident schema, making it the opposite of the least-effort solution.

  • ✗

    Use the Microsoft Sentinel API to pull incidents from Microsoft Defender XDR.

    Why it's wrong here

    The Microsoft Sentinel API is intended to manage existing Sentinel resources, such as incidents, analytic rules, and watchlists; it does not offer a native push/pull endpoint to import incidents from Microsoft Defender XDR. To use this option, you would have to write custom code that calls the Defender Graph APIs to retrieve incidents and then separately creates Sentinel incidents via REST calls, resulting in a brittle integration with no built-in synchronization of incident status or ownership across the two portals.

  • ✗

    Enable raw data ingestion from Microsoft Defender for Endpoint to Microsoft Sentinel.

    Why it's wrong here

    Enabling raw data ingestion from Microsoft Defender for Endpoint brings in device-level events like DeviceLogonEvents and DeviceAlertEvents, as well as raw alert tables, but not the correlated Microsoft 365 Defender incident objects that aggregate alerts across multiple products. This approach is valuable for hunting and querying, but it does not synchronize incident state, severity, or owner, and it misses all non-endpoint threats because the ingestion path is limited to the MDE schema.

  • ✓

    Enable the Microsoft Defender XDR data connector in Microsoft Sentinel.

    Why this is correct

    The Microsoft Defender XDR data connector is the supported, out-of-the-box integration that automatically imports incidents and alerts generated by Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps into Microsoft Sentinel. It leverages the Microsoft Graph security API, preserves the full incident schema, and provides bidirectional synchronization of incident status and comments between Sentinel and the Microsoft 365 Defender portal, requiring no custom code and minimal configuration.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.