SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You need to ensure that security incidents from Defender for Cloud are automatically sent to Sentinel. What should you configure?
⚠ Common exam trap
Many candidates confuse the Microsoft Defender for Cloud data connector with the Microsoft 365 Defender data connector, mistakenly thinking that all 'Defender' services are covered by a single connector, when in fact each has its own dedicated connector for specific alert sources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the Microsoft Defender for Cloud data connector
The Microsoft Defender for Cloud data connector is the correct choice because it is specifically designed to ingest security alerts and incidents from Defender for Cloud into Microsoft Sentinel. This connector enables automatic synchronization of Defender for Cloud's security findings, ensuring that incidents are created in Sentinel without manual intervention or custom infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the Azure Active Directory data connector
Why it's wrong here
The Azure Active Directory data connector ingests identity and access telemetry, specifically sign-in logs, audit logs, and provisioning logs, into Microsoft Sentinel. These logs provide visibility into authentication-related threats such as risky sign-ins and password spray, but they do not include security alerts or incidents generated by Microsoft Defender for Cloud. Therefore, selecting this connector would leave Defender for Cloud detections entirely absent from Sentinel, making it an incorrect choice for this requirement.
- ✓
Configure the Microsoft Defender for Cloud data connector
Why this is correct
The Microsoft Defender for Cloud data connector is the native, purpose-built integration that ingests Defender for Cloud security alerts, recommendations, and incidents directly into Microsoft Sentinel. It requires no extra infrastructure or custom code, automatically streaming alerts from Azure, on-premises, and other cloud workloads protected by Defender for Cloud, and it supports bidirectional status synchronization. This is the correct connector because it directly satisfies the requirement to ingest Defender for Cloud incidents into Sentinel.
- ✗
Create an Azure Event Hub and push Defender for Cloud alerts to Sentinel via a custom connector
Why it's wrong here
An Azure Event Hub with a custom connector would require manual configuration and ongoing maintenance to forward Defender for Cloud alerts, whereas the native data connector in Sentinel automatically ingests these alerts via the built-in "Security Events" or "Defender for Cloud" connector without additional infrastructure. This option is tempting because Event Hubs are commonly used for streaming high-volume telemetry from various sources into Sentinel, and a custom connector could be the correct choice if the alerts needed transformation or enrichment before ingestion, or if the source was a third-party system lacking a native integration.
- ✗
Configure the Microsoft 365 Defender data connector
Why it's wrong here
The Microsoft 365 Defender data connector ingests incidents and alerts from the Microsoft 365 Defender suite, which covers endpoints, Office 365, identity, and cloud apps, but it does not ingest alerts from Microsoft Defender for Cloud. Defender for Cloud is a separate cloud security posture management (CSPM) and workload protection platform, so its alerts are not part of Microsoft 365 Defender's telemetry. Consequently, configuring this connector would route the wrong data source, leaving cloud workload alerts unintegrated with Sentinel and demonstrating a common product confusion.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.