Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Which THREE are valid methods to ingest data into Microsoft Sentinel? (Select three.)

⚠ Common exam trap

Test-takers frequently confuse Azure CLI or Azure Data Factory as valid ingestion methods because they are common Azure tools, but neither directly sends log data to Sentinel's ingestion pipeline.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Sentinel Data Collector API

The Microsoft Sentinel Data Collector API is a valid ingestion method because it allows custom logs and data sources to be sent directly to Sentinel via a RESTful API endpoint. This is commonly used for non-standard data sources that do not have built-in connectors, enabling organizations to ingest data from custom applications or legacy systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Sentinel Data Collector API

    Why this is correct

    The Microsoft Sentinel Data Collector API is a valid ingestion method because it provides a direct REST endpoint for sending custom and third-party log sources into a Log Analytics workspace, which Sentinel monitors. It accepts structured data formats such as JSON, and supports the creation of custom log tables, making it essential for integrating proprietary systems or hardening existing connectors. The API uses Microsoft Entra ID authentication and can be invoked from automation scripts or security tools, enabling near real-time log upload without requiring an agent.

  • ✗

    Azure CLI

    Why it's wrong here

    Azure CLI is a command-line tool used to create, configure, and manage Azure resources via shell commands, not a method for ingesting data into Microsoft Sentinel. While you can use Azure CLI to trigger resource deployments or run scripts that call the Data Collector API, the tool itself does not provide a data plane endpoint for log upload. Thus, Azure CLI is a management plane utility, not a direct ingestion mechanism, and should not be confused with agent-based or API-based log collection.

  • ✓

    Common Event Format (CEF) over Syslog

    Why this is correct

    Common Event Format (CEF) over Syslog is a valid ingestion method because CEF is an industry-standard event format used by many security appliances, and Sentinel can receive CEF messages forwarded via Syslog. The Log Analytics agent or Azure Monitor Agent parses the incoming Syslog packets, extracts the CEF headers and extension fields, and maps them to standard Sentinel tables. This method is widely used for firewalls, intrusion detection systems, and other network security devices, as it enables log correlation and threat detection without deploying custom parsers.

  • ✗

    Azure Data Factory

    Why it's wrong here

    Azure Data Factory is not a direct ingestion method for Microsoft Sentinel because it is an extract-transform-load (ETL) and orchestration service designed for data pipelines between data stores, not for sending security logs to the Sentinel ingestion pipeline. While Data Factory can move data to a storage account that Sentinel might later collect from, this would require intermediate steps and is not a native data connector or ingestion API. Sentinel's intended ingestion paths include agents, the Data Collector API, and built-in data connectors, so Data Factory is an indirect and incorrect answer for direct data ingestion.

  • ✓

    Azure Monitor Agent

    Why this is correct

    The Azure Monitor Agent is a valid ingestion method because it collects logs and performance metrics from Windows and Linux virtual machines and delivers them directly to Azure Monitor Log Analytics workspaces, including those used by Microsoft Sentinel. It replaced the legacy Log Analytics agent and is configured via Data Collection Rules (DCRs) that define which log files, Syslog streams, and Windows Event logs to forward. In Sentinel, the AMA is used by several built-in connectors to stream off-machine telemetry, making it a modern and supported ingestion path.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.