SC-200 Manage a security operations environment Practice Question
Your organization wants to use Microsoft Sentinel's built-in threat intelligence feeds to enrich alerts. Which data connector should you enable?
⚠ Common exam trap
Candidates often confuse 'threat intelligence feeds' with 'security alerts from Microsoft products,' leading them to choose the Microsoft 365 Defender or Defender for Cloud connectors, which ingest alerts but not the external threat intelligence indicators used for enrichment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat Intelligence - TAXII connector.
The Threat Intelligence - TAXII connector is the correct choice because it ingests threat intelligence feeds from STIX/TAXII servers, which are the standard protocol (Trusted Automated eXchange of Intelligence Indicator) used by built-in threat intelligence feeds. This connector allows Microsoft Sentinel to pull indicators of compromise (IOCs) from external threat intelligence sources, enriching alerts with context like malicious IPs, domains, or hashes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Office 365 connector.
Why it's wrong here
The Office 365 connector is a data connector for Microsoft 365 audit logs, capturing user, admin, and system activity from Exchange Online, SharePoint Online, and Teams. It does not natively ingest STIX/TAXII threat intelligence feeds or external indicator data, so it cannot satisfy a requirement to import threat intelligence indicators. Its focus is operational auditing and user behavior, not structured indicator ingestion.
- ✓
Threat Intelligence - TAXII connector.
Why this is correct
The Threat Intelligence - TAXII connector is the built-in Sentinel connector designed to pull structured threat indicators (STIX objects) from TAXII 2.0/2.1 feeds, such as those from trusted providers. It automatically ingests observables and indicators of compromise into the ThreatIntelligenceIndicator table, enabling analytics rules, threat hunting, and workbooks to reference up-to-date external threat intel. This directly meets the requirement for ingesting external threat intelligence feeds.
- ✗
Microsoft 365 Defender connector.
Why it's wrong here
The Microsoft 365 Defender connector ingests incidents and alerts from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps into Sentinel. While these are security events, they are not threat intelligence indicators in STIX format and do not originate from TAXII feeds. Using this connector would create incidents and alerts rather than populate the ThreatIntelligenceIndicator table, so it cannot serve as a threat intelligence source.
- ✗
Microsoft Defender for Cloud connector.
Why it's wrong here
The Defender for Cloud connector brings in security alerts and posture recommendations from Azure and hybrid cloud workloads, but it is not a threat intelligence data source. It relies on Defender for Cloud's detection engines and cloud security signals, not on external TAXII/STIX indicator feeds, so it cannot be used to import threat intelligence indicators. This connector serves a different purpose—cloud workload protection—not indicator collection for threat intelligence.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.