SC-200 Manage a security operations environment Practice Question
Your SOC uses Microsoft Sentinel and Microsoft Defender XDR. You need to ensure that all incidents from Defender XDR are automatically synchronized to Sentinel. You have enabled the Defender XDR connector. However, some incidents are not appearing. What should you check first?
⚠ Common exam trap
Watch out — candidates often assume the connector is fully functional once enabled, overlooking the granular filter settings that control which incidents are actually ingested.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the connector's data filter settings for severity or status.
The Defender XDR connector in Microsoft Sentinel allows filtering of incidents based on severity and status during configuration. If incidents are not appearing, the most common cause is that the connector's data filter settings are excluding them—for example, filtering out 'Informational' severity or 'Resolved' status incidents. This is the first thing to check because the connector is enabled and working, but the filter is preventing synchronization of certain incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Check the connector's data filter settings for severity or status.
Why this is correct
The Microsoft Defender XDR connector in Sentinel exposes data filter settings that directly dictate which incidents are ingested based on severity and status. If an incident is missing, the most likely culprit is that its severity or status value is filtered out at the connector level. This filter operates before the incident ever reaches Sentinel, so no other workspace component would have a chance to ingest it.
- ✗
Confirm that the incident is displayed in a Sentinel workbook.
Why it's wrong here
Workbooks in Sentinel are purely visualization layers that query data already stored in Log Analytics tables like SecurityIncident. They do not have any influence over which incidents are synchronized or ingested. An incident may be absent from a workbook because the underlying query filters criteria, time range, or data isn't refreshed, not because the sync failed. Therefore, checking a workbook cannot diagnose an ingestion pipeline issue.
- ✗
Ensure that alert grouping is enabled in Sentinel.
Why it's wrong here
Alert grouping in Sentinel is a feature of analytics rules that consolidates multiple alerts into a single incident during the rule's execution. This applies to alerts generated by Sentinel scheduled queries or Microsoft analytics rules, not to incidents originating from Microsoft Defender XDR. The Defender XDR connector synchronizes incidents as cohesive entities from the Microsoft 365 Defender API, so toggling alert grouping has no effect on whether those synced incidents appear.
- ✗
Verify that the Microsoft Defender XDR license is active.
Why it's wrong here
Verifying the Microsoft Defender XDR license is a broad prerequisite check, not a targeted step for a single missing incident. An inactive or expired license would typically halt all incident synchronization from Defender XDR, resulting in a systemic absence, not an isolated gap. If other incidents from Defender XDR are flowing into Sentinel, the license is almost certainly active, and the missing incident is more likely caused by connector filters or a specific status/severity exclusion.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.