Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Which TWO of the following are valid methods to ingest data into Microsoft Sentinel? (Select two.)

⚠ Common exam trap

Many candidates confuse Azure Policy (which enforces rules) with diagnostic settings or data connectors (which actually forward logs), leading them to select Option D incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using the Log Analytics agent to send custom logs.

Option A is correct because the Log Analytics agent (MMA/AMA) can be installed on machines to collect custom logs and Windows/Linux events and forward them to the Log Analytics workspace that backs Microsoft Sentinel, including custom log ingestion via the Log Analytics Data Collector API or custom tables. Option E is correct because Microsoft Sentinel ingests data through data connectors, many of which are available from the Content Hub (e.g., Microsoft 365 Defender, Azure Activity, AWS, syslog via AMA), and these connectors are the primary supported ingestion method. Option B is not a valid ingestion method because Azure PowerShell cmdlets manage resources and configuration but do not stream event data directly into Sentinel; ingestion occurs via agents, connectors, or the Data Collector API. Option C is not valid because Power BI is a visualization and reporting tool, not a data streaming or ingestion pipeline into Sentinel. Option D is not valid because Azure Policy enforces governance and compliance on resources; it does not forward logs to Microsoft Sentinel, though diagnostic settings or connectors are used for that purpose.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Using the Log Analytics agent to send custom logs.

    Why this is correct

    Custom logs are a legitimate ingestion path in Microsoft Sentinel because the Log Analytics agent can be configured to monitor specific local text files and send their contents to an Azure Log Analytics workspace. Since Sentinel is built on a Log Analytics workspace, data collected by this agent is automatically available for security analytics. This method is useful for legacy on-premises or IaaS workloads where installing an agent is feasible, and it is a first-class ingestion method for custom log sources.

  • ✗

    Using the Azure PowerShell cmdlets to send events directly.

    Why it's wrong here

    Azure PowerShell cmdlets are management APIs, not a data-plane ingestion mechanism; there is no 'Send-SentinelLog' cmdlet that ships raw events directly into Sentinel. A custom script could call the Log Analytics HTTP Data Collector REST API, but that would be using the API, not the PowerShell cmdlets themselves. Therefore, this option fails as a valid native ingestion method.

  • ✗

    Using Power BI to stream data.

    Why it's wrong here

    Power BI serves as a report and dashboard layer that reads from data sources, including Log Analytics, via streaming datasets or SQL queries; it has no sink interface that writes into Sentinel. Because its architecture is designed to query and visualize data rather than collect telemetry, using Power BI would create a reverse data flow — pulling data out of the workspace, not pushing it in. Consequently, it is not an ingestion method for security logs.

  • ✗

    Using Azure Policy to forward logs.

    Why it's wrong here

    Azure Policy is a governance service that evaluates resources against rules and can apply effects such as audit or deployIfNotExists to remediate configuration, like enabling diagnostic settings on Azure resources. While a policy assignment can indirectly cause diagnostic logs to flow to a Log Analytics workspace, the policy engine itself does not directly forward log data to Sentinel; the actual transport is performed by the Azure diagnostics extension or the resource provider. Thus, Policy is not a direct ingestion method.

  • ✓

    Using a data connector from the content hub.

    Why this is correct

    The content hub is the central location in Sentinel where you can browse, install, and manage solutions that include data connectors, such as for Microsoft 365 Defender, AWS CloudTrail, or Cisco Umbrella. Once a solution is deployed, its data connector can establish an ingestion pipeline via native APIs, Azure Event Hubs, or a Log Analytics agent — making it the primary and most common way to connect supported security sources. For this reason, using a data connector from the content hub is a valid and recommended ingestion method.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.