Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Manage identity and access Practice Question

A security operations team uses Microsoft Sentinel to centralize security monitoring across their hybrid environment. They need to ingest AWS CloudTrail logs from an Amazon Web Services account to detect suspicious activities in their AWS environment. Which data connector should they configure in Microsoft Sentinel?

⚠ Common exam trap

Many exam-takers confuse the Azure Activity log connector with a generic cloud activity log connector, but it only works for Azure, not for AWS CloudTrail.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail connector

The AWS CloudTrail connector is the correct data connector for ingesting AWS CloudTrail logs into Microsoft Sentinel. It requires configuring an S3 bucket in AWS to receive CloudTrail logs and then connecting that bucket to Sentinel via the connector, enabling the detection of suspicious activities such as unauthorized API calls or privilege escalations in the AWS environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Activity log connector

    Why it's wrong here

    The Azure Activity log connector is designed for Azure subscription-level administrative events, such as resource creation, writes, and deletes, streamed through Azure Monitor diagnostic settings. It cannot access or parse AWS CloudTrail logs because it has no integration with AWS APIs, S3 buckets, or the CloudTrail service. In a multi-cloud environment, this connector would ingest Azure activity only and leave AWS event coverage entirely absent.

  • ✓

    AWS CloudTrail connector

    Why this is correct

    The AWS CloudTrail connector is the purpose-built Data Connector in Microsoft Sentinel that ingests CloudTrail management and data events by reading a trail's Amazon S3 bucket, with optional SQS queue delivery for near real-time event collection. It requires you to create an AWS IAM role (with a cross-account or same-account trust) and configure the trail to forward logs to Sentinel, after which the connector normalizes AWS logs into the AWSCloudTrail table. This makes it the only option among these that directly supports the centralization of AWS security logs into Sentinel.

  • ✗

    Syslog connector

    Why it's wrong here

    The Syslog connector is used for on-premises Linux appliances and security devices that emit RFC 3164 or RFC 5424 syslog messages, which a Linux agent forwards to Sentinel over TCP or UDP (with a TLS option). AWS CloudTrail logs are delivered as JSON files to an S3 bucket and are not streamed as syslog, so there is no way for the Syslog connector to subscribe to or receive those events. Even if you tried to forward CloudTrail files to Syslog, you would need a separate extraction layer, and the connector would not automatically parse the JSON or map it to Sentinel's normalized schemas.

  • ✗

    Common Event Format (CEF) connector

    Why it's wrong here

    The Common Event Format (CEF) connector ingests security events from appliances that output the CEF event format (e.g., Palo Alto, Check Point, Fortinet) via syslog, with a Linux agent running the CEF forwarder to deliver them to Sentinel. AWS CloudTrail uses a JSON-based file format in an S3 bucket, not CEF, and the CloudTrail connector does not translate or relay CEF syslog messages. Relying on CEF would require converting CloudTrail's raw records into CEF and setting up an intermediary, which is far more complex and not supported natively.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.