Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

You are configuring Microsoft Sentinel data connectors. Which data connector should you use to ingest logs from Microsoft Entra ID (Azure AD) audit logs and sign-in logs?

⚠ Common exam trap

Candidates often confuse the Azure Activity connector (which logs Azure resource management actions) with the Entra ID connector (which logs identity and authentication events), leading them to incorrectly select Option C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID connector

The Microsoft Entra ID connector (formerly Azure AD connector) is specifically designed to ingest both audit logs and sign-in logs from Microsoft Entra ID into Microsoft Sentinel. This connector uses the Microsoft Graph API to pull the data, enabling security monitoring of identity-related activities such as user sign-ins, directory changes, and risky sign-in events. The other connectors either focus on different data sources or do not capture the full set of Entra ID logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Office 365 connector

    Why it's wrong here

    The Office 365 connector subscribes to the Office 365 Management Activity API and ingests user, admin, and system activity from Exchange Online, SharePoint Online, and Teams — such as mail messages, file operations, and team events. It does not collect Microsoft Entra ID directory audit records or interactive sign-in events. Although both reside in a Microsoft 365 tenant, the data source APIs are separate, so this connector cannot satisfy the requirement for identity log ingestion.

  • ✗

    Microsoft Defender XDR connector

    Why it's wrong here

    The Microsoft Defender XDR connector ingests high-fidelity incident and alert metadata from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and other Defender services via the Microsoft 365 Defender API. It provides security signals and resolved alert details, but it does not stream the raw Entra ID sign-in and audit events. Choosing it would only bring defensive alerting output, not the underlying identity log records needed for complete directory auditing.

  • ✗

    Azure Activity connector

    Why it's wrong here

    The Azure Activity connector pulls subscription-level operational events logged by Azure Resource Manager, such as resource creation, deletion, RBAC changes, and security policy modifications. These control-plane activities describe actions taken on Azure resources, not user authentication sessions or directory object changes inside Microsoft Entra ID. Because Entra ID sign-in and audit logs are identity-plane telemetry, this connector is not a source for them.

  • ✓

    Microsoft Entra ID connector

    Why this is correct

    The Microsoft Entra ID connector uses the Microsoft Graph API to stream both sign-in reports and directory audit logs into Microsoft Sentinel. Ingested data populates tables such as SigninLogs and AuditLogs, enabling detection rules for suspicious logons, MFA failures, and tenant configuration changes. This is the directly appropriate data source for monitoring identity behavior in Microsoft Entra ID.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.