Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Manage identity and access Practice Question

An organization has deployed Microsoft Sentinel as their SIEM. They need to ingest audit logs from their Amazon Web Services (AWS) environment, including CloudTrail logs. Which data connector should they use in Microsoft Sentinel to collect these logs?

⚠ Common exam trap

Many candidates confuse the generic 'AWS S3 connector' with CloudTrail log ingestion, but CloudTrail logs are ingested via the dedicated 'Amazon Web Services' connector, not through direct S3 bucket access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Web Services connector

The Amazon Web Services connector is the correct data connector in Microsoft Sentinel for ingesting AWS audit logs, including CloudTrail logs. It establishes a connection to AWS by requiring a role ARN and external ID, enabling Sentinel to pull CloudTrail events via the AWS API. This connector specifically supports CloudTrail management and data events, making it the appropriate choice for audit log ingestion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon Web Services connector

    Why this is correct

    The correct connector in Microsoft Sentinel is named 'Amazon Web Services,' and it is specifically designed to ingest AWS CloudTrail audit logs into Sentinel. This connector uses an S3 bucket as the log source and SQS for automated notifications, while also requiring an AWS role for cross-account access. Its official display name in the Sentinel data connectors gallery is 'Amazon Web Services (AWS),' which is why it is the precise answer.

  • ✗

    AWS S3 connector

    Why it's wrong here

    There is no standalone 'AWS S3' connector; S3 is simply the storage service where CloudTrail logs are delivered, not a log source itself. Although the AWS connector relies on an S3 bucket to retrieve logs, the connector's official name and configuration are under 'Amazon Web Services,' and selecting 'AWS S3' would fail to recognize the necessary CloudTrail and SQS components. Thus, this option incorrectly identifies the underlying service as the connector name.

  • ✗

    Azure Sentinel to AWS connector

    Why it's wrong here

    'Azure Sentinel to AWS connector' is not a recognized or standard connector name in the Microsoft Sentinel catalog. The phrasing implies a direction from Sentinel to AWS, whereas the actual ingestion flow is from AWS to Sentinel via the 'Amazon Web Services' connector. Since Sentinel's data connectors are named for the source platform, not for the target or a custom integration path, this option is incorrect.

  • ✗

    CloudTrail connector

    Why it's wrong here

    Although AWS CloudTrail generates the audit logs that Sentinel ingests, the connector itself is not named 'CloudTrail.' In the Sentinel data connectors gallery, the connector is officially listed as 'Amazon Web Services' and it ingests CloudTrail data along with other AWS service logs. Referring to it as the 'CloudTrail connector' conflates the log source with the connector name, making this answer incorrect.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.