Courseiva

SC-200 Manage a security operations environment Practice Question

Your SOC uses Microsoft Sentinel and Microsoft Defender for Identity (MDI). You have configured MDI to send alerts to Microsoft 365 Defender. From there, Microsoft Sentinel ingests the alerts via the Microsoft 365 Defender connector. You want to ensure that when MDI detects a suspicious activity, the incident in Microsoft Sentinel is created within 5 minutes. Which factors should you consider?

⚠ Common exam trap

Watch out — candidates often assume MDI alerts flow directly into Microsoft Sentinel with minimal delay, overlooking the polling-based Microsoft 365 Defender connector and the scheduled analytics rule that together introduce cumulative latency.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The latency depends on the Microsoft 365 Defender connector's polling interval and the analytics rule's frequency.

The incident creation latency in this architecture depends on two factors: the Microsoft 365 Defender connector's polling interval (which retrieves alerts from Microsoft 365 Defender) and the frequency of the Microsoft Sentinel analytics rule that creates incidents from those ingested alerts. Even if MDI sends alerts quickly to Microsoft 365 Defender, the connector polls at a configurable interval (default every 5 minutes), and the analytics rule runs on its own schedule (typically every 5 minutes). Thus, the total time to incident creation is the sum of these intervals, not a fixed 5 minutes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The latency is determined solely by the MDI sensor health and network speed.

    Why it's wrong here

    While MDI sensor health and network speed influence how soon raw signals reach Microsoft 365 Defender, they do not determine when Sentinel ingests those signals. The connector's polling interval and the scheduled analytics rule that creates incidents introduce additional, independent delays. Thus, latency cannot be attributed solely to sensor health and network speed.

  • ✗

    The incident creation time is controlled by the Microsoft Defender for Cloud Apps connector.

    Why it's wrong here

    The Microsoft Defender for Cloud Apps connector ingests alerts from that cloud access security broker, such as anomalous app activity or session policies; it has no role in MDI's identity-based detection pipeline. MDI alerts are routed through the Microsoft 365 Defender connector, which polls the unified alert API. Therefore, that connector has no bearing on incident creation latency for MDI.

  • ✗

    The incident will be created within 5 minutes because MDI writes directly to Microsoft Sentinel.

    Why it's wrong here

    Microsoft Defender for Identity operates as part of Microsoft 365 Defender, so its alerts are not written directly into Sentinel; they are first aggregated in the M365D alert store. The Microsoft 365 Defender connector then polls these alerts on a fixed interval (typically every few minutes), and only after ingestion does the Microsoft Sentinel analytics rule run on its own schedule. Consequently, incident creation can take longer than five minutes and depends on these two stages.

  • ✓

    The latency depends on the Microsoft 365 Defender connector's polling interval and the analytics rule's frequency.

    Why this is correct

    The end-to-end latency for MDI incident creation in Microsoft Sentinel depends on two sequential factors: the Microsoft 365 Defender connector's polling interval, which determines how frequently alerts are fetched from the unified API, and the frequency of the analytics rule that converts those alerts into incidents. The connector typically polls every few minutes, but that interval is not instant, and the scheduled rule runs on its own cadence (e.g., every 5-15 minutes) based on the configured frequency. Therefore, the total delay is the sum of these intervals, not a fixed duration, and is the primary driver of when the incident appears.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.