SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel. You have configured a data connector to ingest events from a third-party firewall. However, you notice that the logs are not appearing in Sentinel. What is the first thing you should check?
⚠ Common exam trap
SC-200 often tests troubleshooting order — candidates jump to source-side or remediation actions (firewall config, agent reinstall) instead of first using Sentinel's built-in connector health telemetry to localize the fault.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the connector health page in Microsoft Sentinel.
The connector health page in Microsoft Sentinel is the first place to check because it shows whether the data connector is connected, when data was last received, and any ingestion errors. If the connector shows a healthy status but no data arrives, the issue is likely upstream (firewall or agent); if it shows disconnected or error, the problem is with the connector itself. This diagnostic step narrows the fault domain before investigating the firewall or agent.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check the firewall's syslog server configuration.
Why it's wrong here
Checking the firewall's syslog server configuration can reveal whether logs are being forwarded correctly, but this is a secondary troubleshooting step. The unknown variable is whether Microsoft Sentinel's connector is even healthy and receiving the logs. The connector health page should be examined first, as it identifies ingestion failures before examining source device settings.
- ✗
Verify that the workspace is in the correct region.
Why it's wrong here
The Azure region of the Log Analytics workspace is an unlikely cause of missing logs because Sentinel ingests syslog/CEF data over the internet from any region. As long as the firewall can resolve and reach the workspace's FQDN and port 443, logs will be received. Region mainly affects latency or regulatory compliance, not the absence of data.
- ✗
Reinstall the Log Analytics agent on the firewall.
Why it's wrong here
Reinstalling the Log Analytics agent on the firewall is generally wrong because most firewalls (e.g., Palo Alto, Fortinet) do not run a Log Analytics agent; they forward logs as syslog or CEF to a collector. The collector VM uses the Log Analytics agent, but the firewall itself doesn't. Reinstalling the agent on the firewall would not address the data flow.
- ✓
Check the connector health page in Microsoft Sentinel.
Why this is correct
Checking the connector health page in Microsoft Sentinel is the correct first step because it provides a centralized view of each data connector's status, including whether it's connected, when the last event was received, and any ingestion errors. This page also shows the connector type, relevant log tables, and version information. If the connector is healthy, the issue likely lies in the source device or forwarder; if unhealthy, you can see specific error messages and take targeted corrective action.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.