SC-200 Perform threat hunting Practice Question
Your threat hunt involves correlating alerts from Microsoft Defender for Cloud Apps with Microsoft Defender for Endpoint. Which Microsoft Sentinel integration should you use to unify these alerts for hunting?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel's unified analytics rules and incident creation
Microsoft Sentinel provides built-in connectors and analytics rules to correlate alerts across Microsoft Defender XDR, including Defender for Cloud Apps and Defender for Endpoint. Option B (Power Automate) can automate workflows but does not provide a unified hunting experience or correlation. Option C (Microsoft Graph API) is programmatic and can retrieve alerts, but it is not a unified correlation tool. Option D (Azure Monitor Workbooks) visualizes data but does not correlate or unify alerts for hunting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Sentinel's unified analytics rules and incident creation
Why this is correct
Unified analytics rules in Microsoft Sentinel correlate alerts from multiple sources, including Microsoft Defender for Cloud Apps and Microsoft Defender for Endpoint, and group them into a single incident. This satisfies the requirement to unify cross-product alerts for hunting rather than viewing them separately.
- ✗
Power Automate flows to merge alerts
Why it's wrong here
Power Automate orchestrates actions between services; it does not ingest Defender alerts into Sentinel's hunting tables. The Microsoft Defender XDR connector performs that ingestion, surfacing correlated incidents for KQL hunting. Power Automate suits automated response workflows, such as creating tickets when an incident is raised.
- ✗
Microsoft Graph API to pull alerts into a custom database
Why it's wrong here
Microsoft Graph API exposes raw alert endpoints but provides no native correlation, entity mapping or incident grouping, so hunting requires manual joins in an external store. It suits custom automation or reporting pipelines, not unified cross-product alert correlation within Microsoft Sentinel.
- ✗
Azure Monitor Workbooks to display alerts side by side
Why it's wrong here
Workbooks render dashboards; they query Log Analytics but do not unify or correlate alerts across Defender services. The stem needs the Microsoft Defender XDR connector, which streams both products' incidents into one Sentinel workspace. Workbooks suit visual reporting over existing data, not cross-product alert correlation.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.