SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You need to ensure that all security alerts from Defender for Cloud are automatically ingested into Sentinel with the least latency. What should you configure?
⚠ Common exam trap
The trap here is that candidates often overcomplicate the solution by choosing custom integration methods (Logic Apps, API polling) or multi-step exports, failing to recognize that Microsoft's native data connector is specifically designed for this exact purpose with minimal latency and configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the Microsoft Defender for Cloud data connector in Sentinel to stream alerts.
The Microsoft Defender for Cloud data connector in Microsoft Sentinel provides a native, direct integration that streams security alerts from Defender for Cloud into Sentinel with near-real-time latency. This connector uses the underlying Azure Resource Graph and alert APIs to push alerts automatically, eliminating the need for custom polling or additional orchestration, which ensures the least possible ingestion delay.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a custom API connector in Sentinel to pull alerts from Defender for Cloud REST API every 5 minutes.
Why it's wrong here
A custom API connector that polls the Defender for Cloud REST API every 5 minutes introduces up to 5 minutes of ingestion latency because Sentinel must pull on a fixed schedule, and the connector must handle pagination, rate limiting, and stateful offset tracking. This polling approach is operationally complex and inferior to the built-in data connector, which streams alerts as they occur.
- ✗
Enable continuous export in Defender for Cloud to send alerts to a Log Analytics workspace and then create a scheduled query in Sentinel.
Why it's wrong here
Continuous export sends Defender for Cloud alerts to a Log Analytics workspace, but you still need a scheduled query or analytics rule to process those alerts in Sentinel, and the query runs on an interval rather than receiving events instantly. This adds latency and requires you to maintain a separate export configuration and query logic, whereas the native Defender for Cloud connector automatically delivers alerts to the SecurityAlert table with minimal delay.
- ✓
Use the Microsoft Defender for Cloud data connector in Sentinel to stream alerts.
Why this is correct
The Microsoft Defender for Cloud data connector is a built-in, native integration that streams security alerts and recommendations directly into Sentinel's SecurityAlert table in near real-time, without requiring custom code or polling intervals. It automatically synchronizes alert status, severity, and entities, allowing Sentinel to create incidents immediately and making it the lowest-latency, lowest-maintenance approach.
- ✗
Create a Logic App that triggers on Defender for Cloud alerts and sends them to Sentinel via the Azure Monitor HTTP Data Collector API.
Why it's wrong here
While a Logic App can be triggered when Defender for Cloud generates an alert, sending the payload through the Azure Monitor HTTP Data Collector API adds an orchestration layer, meaning each alert must be processed, serialized, and submitted before it reaches Sentinel. This introduces variable latency, potential failure points, and custom log-type maintenance, and it is not as reliable or fast as the purpose-built data connector.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You need to ensure that security alerts from Defender for Cloud are automatically ingested into Sentinel. What should you configure?
medium- A.Enable diagnostic settings on the Defender for Cloud subscription.
- B.Configure the 'Azure Activity' data connector.
- C.Create an automation rule in Sentinel to fetch alerts from Defender for Cloud.
- ✓ D.Add the 'Microsoft Defender for Cloud' data connector in Microsoft Sentinel.
Why D: The 'Microsoft Defender for Cloud' data connector in Microsoft Sentinel is specifically designed to ingest security alerts from Defender for Cloud into Sentinel. When you enable this connector, it automatically synchronizes alerts from all connected Defender for Cloud subscriptions, allowing you to investigate and respond to those alerts within Sentinel's unified security operations environment.
Variation 2. Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You need to ensure that all cloud security alerts are automatically ingested into Sentinel. What should you configure?
medium- A.Configure the Microsoft 365 Defender data connector.
- B.Configure the Azure Activity data connector.
- C.Create a custom log table and a PowerShell script to push alerts.
- ✓ D.Configure the Microsoft Defender for Cloud data connector (Legacy).
Why D: The Microsoft Defender for Cloud data connector (Legacy) is the correct choice because it specifically ingests security alerts from Microsoft Defender for Cloud into Microsoft Sentinel. This connector ensures that all alerts generated by Defender for Cloud's security policies and threat detection are automatically streamed into Sentinel for centralized monitoring and incident response.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.