Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel with a Log Analytics workspace in the East US region. You have deployed the Microsoft Defender for Cloud connector. You notice that security alerts from Defender for Cloud are not appearing as incidents in Sentinel. You have confirmed that the connector is enabled and data is flowing. What is the most likely cause?

⚠ Common exam trap

Many candidates assume enabling the connector automatically creates incidents, but Microsoft Sentinel requires an explicit analytics rule to generate incidents from any data source, including Defender for Cloud alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

You need to create an analytics rule with a rule template that uses the SecurityAlert table.

The Microsoft Defender for Cloud connector ingests security alerts into the Log Analytics workspace's SecurityAlert table, but incidents in Microsoft Sentinel are generated only by analytics rules. Without a configured analytics rule that queries the SecurityAlert table (such as the built-in 'Create incidents based on Microsoft Defender for Cloud alerts' template), no incidents will be created even if data is flowing. Option C correctly identifies this missing step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Sentinel workspace does not have required permissions to create incidents.

    Why it's wrong here

    The Sentinel workspace permissions govern access to Sentinel features, not the act of creating incidents. Incident creation is performed by the analytics rule engine after a rule matches conditions; the workspace itself does not require special permissions to generate incidents. Since data is flowing, the connector and workspace have adequate access, so a permission problem would not explain the absence of incidents. The real issue is that no enabled analytics rule exists to transform incoming SecurityAlert data into incidents.

  • ✗

    There is a delay in incident creation; wait for 24 hours.

    Why it's wrong here

    Analytics rules in Microsoft Sentinel run on a defined schedule, typically every 5 minutes to hourly, and incidents are created soon after the rule runs if the query returns results. A 24-hour delay is not a normal behavior; if no incidents appear, it indicates a configuration gap, not a waiting period. Waiting will not help because the underlying problem is that no analytics rule is enabled to query the SecurityAlert table and create incidents. You should instead verify and enable the appropriate analytics rule template.

  • ✓

    You need to create an analytics rule with a rule template that uses the SecurityAlert table.

    Why this is correct

    Microsoft Sentinel does not automatically create incidents from ingested security alerts; it requires an analytics rule to generate them. The Microsoft Defender for Cloud connector only ingests alerts into the SecurityAlert table in the Log Analytics workspace. To create incidents, you must create or enable an analytics rule that queries the SecurityAlert table and defines the incident properties. Without such a rule, alerts remain as raw log data and never appear in the Incidents queue.

  • ✗

    The Microsoft Defender for Cloud connector is not properly configured.

    Why it's wrong here

    The connector's configuration is responsible for data ingestion, not incident generation. Since data is flowing, the Microsoft Defender for Cloud connector is properly connected and ingesting alerts into the SecurityAlert table. The absence of incidents is not due to connector misconfiguration but because no analytics rule is enabled to query those alerts and create incidents. Even a properly configured connector will not produce incidents unless an appropriate analytics rule is set up.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.