AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Which THREE are valid methods to ingest data into Microsoft Sentinel? (Select three.)
⚠ Common exam trap
Test-takers frequently confuse Azure CLI or Azure Data Factory as valid ingestion methods because they are common Azure tools, but neither directly sends log data to Sentinel's ingestion pipeline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel Data Collector API
The Microsoft Sentinel Data Collector API is a valid ingestion method because it allows custom logs and data sources to be sent directly to Sentinel via a RESTful API endpoint. This is commonly used for non-standard data sources that do not have built-in connectors, enabling organizations to ingest data from custom applications or legacy systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Sentinel Data Collector API
Why this is correct
The Microsoft Sentinel Data Collector API is a valid ingestion method because it provides a direct REST endpoint for sending custom and third-party log sources into a Log Analytics workspace, which Sentinel monitors. It accepts structured data formats such as JSON, and supports the creation of custom log tables, making it essential for integrating proprietary systems or hardening existing connectors. The API uses Microsoft Entra ID authentication and can be invoked from automation scripts or security tools, enabling near real-time log upload without requiring an agent.
- ✗
Azure CLI
Why it's wrong here
Azure CLI is a command-line tool used to create, configure, and manage Azure resources via shell commands, not a method for ingesting data into Microsoft Sentinel. While you can use Azure CLI to trigger resource deployments or run scripts that call the Data Collector API, the tool itself does not provide a data plane endpoint for log upload. Thus, Azure CLI is a management plane utility, not a direct ingestion mechanism, and should not be confused with agent-based or API-based log collection.
- ✓
Common Event Format (CEF) over Syslog
Why this is correct
Common Event Format (CEF) over Syslog is a valid ingestion method because CEF is an industry-standard event format used by many security appliances, and Sentinel can receive CEF messages forwarded via Syslog. The Log Analytics agent or Azure Monitor Agent parses the incoming Syslog packets, extracts the CEF headers and extension fields, and maps them to standard Sentinel tables. This method is widely used for firewalls, intrusion detection systems, and other network security devices, as it enables log correlation and threat detection without deploying custom parsers.
- ✗
Azure Data Factory
Why it's wrong here
Azure Data Factory is not a direct ingestion method for Microsoft Sentinel because it is an extract-transform-load (ETL) and orchestration service designed for data pipelines between data stores, not for sending security logs to the Sentinel ingestion pipeline. While Data Factory can move data to a storage account that Sentinel might later collect from, this would require intermediate steps and is not a native data connector or ingestion API. Sentinel's intended ingestion paths include agents, the Data Collector API, and built-in data connectors, so Data Factory is an indirect and incorrect answer for direct data ingestion.
- ✓
Azure Monitor Agent
Why this is correct
The Azure Monitor Agent is a valid ingestion method because it collects logs and performance metrics from Windows and Linux virtual machines and delivers them directly to Azure Monitor Log Analytics workspaces, including those used by Microsoft Sentinel. It replaced the legacy Log Analytics agent and is configured via Data Collection Rules (DCRs) that define which log files, Syslog streams, and Windows Event logs to forward. In Sentinel, the AMA is used by several built-in connectors to stream off-machine telemetry, making it a modern and supported ingestion path.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.