AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You are configuring Microsoft Sentinel to ingest logs from Microsoft Entra ID. Which two data connectors are necessary to collect sign-in logs and audit logs?
⚠ Common exam trap
A common mix-up: candidates confuse Azure Activity logs (subscription-level) with Microsoft Entra ID Audit logs (tenant-level), or assume Office 365 logs include Microsoft Entra ID sign-in events, when in fact each log type requires its own dedicated connector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Sign-in logs and Microsoft Entra ID Audit logs
To collect sign-in logs and audit logs in Microsoft Sentinel, you need the Microsoft Entra ID Sign-in logs connector for sign-in activity and the Microsoft Entra ID Audit logs connector for directory changes and user management events. These two connectors directly correspond to the two log categories required by the question.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Activity and Microsoft Entra ID Audit logs
Why it's wrong here
The Azure Activity connector ingests control-plane operational events for Azure resources (e.g., resource creation, configuration changes) but does not carry user authentication/sign-in events. Microsoft Entra ID Audit Logs capture directory administration changes (user/group management, role assignments) but also lack sign-in telemetry. Together they omit the required sign-in log data, so they cannot satisfy a security monitoring scenario that needs both authentication and audit information.
- ✗
Office 365 and Microsoft Entra ID Sign-in logs
Why it's wrong here
The Office 365 connector pulls mailbox, SharePoint, Teams, and other Office workload audit records from the Unified Audit Log, but it does not expose Microsoft Entra ID Audit Log entries (e.g., changes to directory objects, security group modifications). While Microsoft Entra ID Sign-in Logs are correctly included, the absence of Microsoft Entra ID Audit Logs means administrative changes to identity configurations would not be ingested. Thus the pair is incomplete for a design requiring both sign-in and directory audit data.
- ✓
Microsoft Entra ID Sign-in logs and Microsoft Entra ID Audit logs
Why this is correct
Microsoft Entra ID Sign-in Logs ingest authentication and authorization events, such as successful and failed user sign-ins, conditional access results, and MFA challenges. Microsoft Entra ID Audit Logs capture all directory-management activities, including user creation, group membership changes, password resets, and application role assignments. These two complementary connectors provide the full AAD security telemetry needed to monitor both user access and administrative changes in Microsoft Sentinel.
- ✗
Security Events and Microsoft Entra ID Sign-in logs
Why it's wrong here
The Security Events connector collects Windows Event Log entries (e.g., 4624 logon events, 4625 failed logons) from Windows VMs and physical servers via the Log Analytics Agent, so it tracks on-premises/VM-level logon activity rather than cloud identity activity. Microsoft Entra ID Sign-in Logs do provide cloud authentication events, but the pair lacks Microsoft Entra ID Audit Logs, which are required for directory change monitoring. Therefore combining VM security events with sign-in logs fails to cover the directory audit component.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.