SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You need to ensure that security alerts from Defender for Cloud are automatically ingested into Sentinel. What should you configure?
⚠ Common exam trap
Candidates often confuse diagnostic settings (which export logs) with data connectors (which import security alerts), leading them to choose Option A instead of the correct data connector in Option D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the 'Microsoft Defender for Cloud' data connector in Microsoft Sentinel.
The 'Microsoft Defender for Cloud' data connector in Microsoft Sentinel is specifically designed to ingest security alerts from Defender for Cloud into Sentinel. When you enable this connector, it automatically synchronizes alerts from all connected Defender for Cloud subscriptions, allowing you to investigate and respond to those alerts within Sentinel's unified security operations environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable diagnostic settings on the Defender for Cloud subscription.
Why it's wrong here
Enabling diagnostic settings on the Defender for Cloud subscription exports platform logs and metrics to a Log Analytics workspace, but this does not establish the native alert-synchronization pipeline used by Microsoft Sentinel. Security alerts from Defender for Cloud are ingested only through the dedicated data connector, which populates the SecurityAlert table and automatically creates incidents. Without that connector, diagnostic settings alone will not make Defender for Cloud alerts appear as Sentinel incidents.
- ✗
Configure the 'Azure Activity' data connector.
Why it's wrong here
The Azure Activity data connector is a separate source that ingests control-plane operation logs, such as VM create/delete and resource policy events, into the AzureActivity table. It does not collect Microsoft Defender for Cloud security alerts, which are stored in the SecurityAlert table. Therefore, adding this connector would provide subscription activity data but leave Defender for Cloud alerts unavailable to your analytics rules.
- ✗
Create an automation rule in Sentinel to fetch alerts from Defender for Cloud.
Why it's wrong here
Automation rules in Microsoft Sentinel work only on incidents that have already been created in the workspace; they cannot pull data from external services like Defender for Cloud. A rule cannot 'fetch' alerts because data ingestion is exclusively performed by data connectors. Instead, automation rules can be used to triage, assign, or run playbooks on incidents after the Defender for Cloud connector has ingested the alerts and created the incidents.
- ✓
Add the 'Microsoft Defender for Cloud' data connector in Microsoft Sentinel.
Why this is correct
The Microsoft Defender for Cloud data connector is the standard, supported method to ingest security alerts from Defender for Cloud into Microsoft Sentinel. It connects to your subscriptions and streams alerts into the SecurityAlert table, while optionally enabling incident creation and bi-directional synchronization of alert status. Once configured, your analytics rules and automation rules can then operate on those alerts directly.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.