AZ-500 Manage identity and access Practice Question
A security operations team uses Microsoft Sentinel to centralize security monitoring across their hybrid environment. They need to ingest AWS CloudTrail logs from an Amazon Web Services account to detect suspicious activities in their AWS environment. Which data connector should they configure in Microsoft Sentinel?
⚠ Common exam trap
Many exam-takers confuse the Azure Activity log connector with a generic cloud activity log connector, but it only works for Azure, not for AWS CloudTrail.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail connector
The AWS CloudTrail connector is the correct data connector for ingesting AWS CloudTrail logs into Microsoft Sentinel. It requires configuring an S3 bucket in AWS to receive CloudTrail logs and then connecting that bucket to Sentinel via the connector, enabling the detection of suspicious activities such as unauthorized API calls or privilege escalations in the AWS environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Activity log connector
Why it's wrong here
The Azure Activity log connector is designed for Azure subscription-level administrative events, such as resource creation, writes, and deletes, streamed through Azure Monitor diagnostic settings. It cannot access or parse AWS CloudTrail logs because it has no integration with AWS APIs, S3 buckets, or the CloudTrail service. In a multi-cloud environment, this connector would ingest Azure activity only and leave AWS event coverage entirely absent.
- ✓
AWS CloudTrail connector
Why this is correct
The AWS CloudTrail connector is the purpose-built Data Connector in Microsoft Sentinel that ingests CloudTrail management and data events by reading a trail's Amazon S3 bucket, with optional SQS queue delivery for near real-time event collection. It requires you to create an AWS IAM role (with a cross-account or same-account trust) and configure the trail to forward logs to Sentinel, after which the connector normalizes AWS logs into the AWSCloudTrail table. This makes it the only option among these that directly supports the centralization of AWS security logs into Sentinel.
- ✗
Syslog connector
Why it's wrong here
The Syslog connector is used for on-premises Linux appliances and security devices that emit RFC 3164 or RFC 5424 syslog messages, which a Linux agent forwards to Sentinel over TCP or UDP (with a TLS option). AWS CloudTrail logs are delivered as JSON files to an S3 bucket and are not streamed as syslog, so there is no way for the Syslog connector to subscribe to or receive those events. Even if you tried to forward CloudTrail files to Syslog, you would need a separate extraction layer, and the connector would not automatically parse the JSON or map it to Sentinel's normalized schemas.
- ✗
Common Event Format (CEF) connector
Why it's wrong here
The Common Event Format (CEF) connector ingests security events from appliances that output the CEF event format (e.g., Palo Alto, Check Point, Fortinet) via syslog, with a Linux agent running the CEF forwarder to deliver them to Sentinel. AWS CloudTrail uses a JSON-based file format in an S3 bucket, not CEF, and the CloudTrail connector does not translate or relay CEF syslog messages. Relying on CEF would require converting CloudTrail's raw records into CEF and setting up an intermediary, which is far more complex and not supported natively.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.