Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You need to ensure that all incidents from Microsoft Defender XDR are synchronized to Microsoft Sentinel with the same status (e.g., 'Active', 'Resolved'). What should you configure?

⚠ Common exam trap

A common mix-up: candidates think a custom playbook or API polling is required for synchronization, not realizing that the official connector already handles bidirectional status updates natively.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Connect Microsoft Defender XDR to Microsoft Sentinel using the official data connector.

The official Microsoft Defender XDR data connector in Microsoft Sentinel automatically synchronizes incidents, including their status (e.g., 'Active', 'Resolved'), bidirectionally. This ensures that any status change in either system is reflected in the other without manual intervention or custom scripting. Option B is correct because it leverages the built-in integration that handles the synchronization natively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a custom playbook to poll Defender XDR API and update Sentinel incidents.

    Why it's wrong here

    Writing a custom playbook that polls the Microsoft Graph/Defender XDR API and then calls the Sentinel incidents API to update records is redundant and fragile. The official Microsoft Defender XDR data connector already streams incident telemetry into Sentinel and automatically propagates status changes in both directions, eliminating the need to manage API throttling, pagination, and authentication scopes. Maintaining a custom poller also introduces latency and an extra failure domain that can delay incident closure and incur unnecessary Logic App execution costs.

  • ✓

    Connect Microsoft Defender XDR to Microsoft Sentinel using the official data connector.

    Why this is correct

    Ingesting Microsoft Defender XDR incidents through its official data connector is the supported first-party integration path and the only method that provides bi-directional synchronization natively. After you enable the connector, incidents created in Defender XDR appear in Sentinel and any analyst status update—such as resolved or closed—is written back to Defender XDR, and vice versa, through an automated sync mechanism. This approach preserves the full incident context and correlation across Defender workloads instead of just importing raw alerts.

  • ✗

    Manually update status in both systems.

    Why it's wrong here

    Manually updating an incident's status in both Microsoft Sentinel and Microsoft Defender XDR is operationally unsupportable because it depends on analysts remembering to reconcile two separate consoles during each change. Any missed or delayed update splits the incident lifecycle, breaks the audit trail, and lets teams in the two portals act on conflicting states, extending mean time to respond and risking non-compliance. Automation via the built-in connector is the only reliable way to keep these systems aligned in real time.

  • ✗

    Disable the Microsoft Defender XDR connector and use separate connectors for each workload.

    Why it's wrong here

    Disabling the unified Microsoft Defender XDR connector to use workload-specific connectors would fragment the same attack narrative into individual alert tables and strip away incident correlation and bi-directional status synchronization. Each product connector only streams raw alerts into Log Analytics; without the unified incident stream, Sentinel cannot close out a Defender incident when the analyst closes the matching Sentinel incident. It also multiplies ingestion costs and creates duplicate alerts that degrade detection analytics.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You need to ensure that incidents created in Microsoft Defender XDR are automatically synchronized to Microsoft Sentinel with the least administrative effort. What should you configure?

medium
  • A.Create a Logic App that uses the Microsoft Defender XDR API to fetch incidents and push them to Microsoft Sentinel.
  • B.Use the Microsoft Sentinel API to pull incidents from Microsoft Defender XDR.
  • C.Enable raw data ingestion from Microsoft Defender for Endpoint to Microsoft Sentinel.
  • ✓ D.Enable the Microsoft Defender XDR data connector in Microsoft Sentinel.

Why D: The Microsoft Defender XDR data connector in Microsoft Sentinel provides a built-in, one-click integration that automatically synchronizes incidents from Microsoft Defender XDR to Microsoft Sentinel with no custom development required. This connector uses the Microsoft Graph Security API to ingest incidents, alerts, and evidence, ensuring seamless bidirectional synchronization with the least administrative effort.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.