Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You need to ensure that all cloud security alerts are automatically ingested into Sentinel. What should you configure?

⚠ Common exam trap

Candidates often confuse the Microsoft 365 Defender data connector (which handles endpoint and office alerts) with the Defender for Cloud data connector (which handles cloud security alerts), leading them to select option A incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the Microsoft Defender for Cloud data connector (Legacy).

The Microsoft Defender for Cloud data connector (Legacy) is the correct choice because it specifically ingests security alerts from Microsoft Defender for Cloud into Microsoft Sentinel. This connector ensures that all alerts generated by Defender for Cloud's security policies and threat detection are automatically streamed into Sentinel for centralized monitoring and incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the Microsoft 365 Defender data connector.

    Why it's wrong here

    The Microsoft 365 Defender data connector ingests incidents and alerts generated by Microsoft 365 Defender (MDO, MDE, MDI, and MCAS), representing endpoint, email, identity, and collaboration threats. It does not consume Defender for Cloud's cloud workload protection alerts such as VM threat detection or storage account credential exposure. Therefore, configuring it would fail to meet the requirement to ingest all cloud security alerts from Defender for Cloud into Sentinel; the legacy Defender for Cloud connector is the dedicated pipeline for those alerts.

  • ✗

    Configure the Azure Activity data connector.

    Why it's wrong here

    The Azure Activity data connector collects the subscription-level control-plane audit log, including operations like resource creation, VM state changes, and administrative actions. These events may provide context for insider threats, but they are not the security alerts produced by Defender for Cloud, which are vulnerability detections and behavioral signals from workloads. Using this connector alone would leave actual Defender for Cloud security findings uncollected, as it does not map to the SecurityAlert table.

  • ✗

    Create a custom log table and a PowerShell script to push alerts.

    Why it's wrong here

    Creating a custom log table and a PowerShell script to push alerts would require developing and maintaining an Azure Automation runbook or external script, handling authentication, retries, and the security alert schema manually. This approach is not the purpose-built integrated method; Sentinel already provides a managed data connector that automatically streams Defender for Cloud alerts with a normalized schema and native ingestion. It would also be a brittle, high-latency workaround that contradicts the requirement for automatic, supported ingestion.

  • ✓

    Configure the Microsoft Defender for Cloud data connector (Legacy).

    Why this is correct

    The Microsoft Defender for Cloud data connector (Legacy) directly ingests security alerts from Defender for Cloud into Microsoft Sentinel via the Azure Resource Graph API, satisfying the requirement for automatic ingestion without manual forwarding. This connector specifically handles cloud security alerts, not broader signals, aligning with the stem’s constraint of ingesting all cloud security alerts from Defender for Cloud into Sentinel.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.