Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Your organization uses Microsoft Sentinel for security operations. You need to ensure that Sentinel can ingest logs from Microsoft 365 Defender (XDR) and Microsoft Entra ID. Which THREE data connectors should you enable? (Choose three.)

⚠ Common exam trap

Candidates often confuse Microsoft Purview Information Protection or Intune as security log sources, when in fact they are governance and management tools without native data connectors for Sentinel's security log ingestion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Endpoint

Microsoft Defender for Endpoint is a correct data connector because it ingests endpoint detection and response (EDR) logs from Windows, macOS, and Linux devices into Microsoft Sentinel. This integration allows security operations to correlate endpoint alerts with other signals, enabling advanced hunting and automated incident response across the Microsoft 365 Defender ecosystem.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Defender for Endpoint

    Why this is correct

    The Microsoft Defender for Endpoint connector is a built-in Sentinel data source that directly ingests endpoint detection and response telemetry, including tables such as DeviceLogonEvents, DeviceProcessEvents, and DeviceNetworkEvents. These raw Advanced Hunting events enable detections for malware, lateral movement, and other endpoint attacks. Without this connector, endpoint visibility would rely on manual log forwarding or third-party agents.

  • ✗

    Microsoft Purview Information Protection

    Why it's wrong here

    Microsoft Purview Information Protection is a data governance and classification service that applies sensitivity labels, not a source of raw security telemetry. Sentinel has no built-in 'Purview Information Protection' data connector; at best, label-related activities appear indirectly as audit log records ingested through the Microsoft 365 or Unified Audit Log connector. Therefore, it cannot be selected as a direct data source for Sentinel.

  • ✓

    Microsoft Entra ID (formerly Azure AD)

    Why this is correct

    The Microsoft Entra ID connector (formerly Azure AD) enables Sentinel to collect identity and directory telemetry, specifically sign-in logs, audit logs for administrative actions, and provisioning events. This connector is essential for detecting suspicious sign-ins, privilege changes, and compromised accounts. It streams data directly into the SigninLogs and AuditLogs tables for analytics.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune does not have a standalone Sentinel data connector; its device management audit logs are not available as an independent table. Intune-related telemetry can only reach Sentinel indirectly through the Microsoft 365 Defender connector or by using the Microsoft Graph API with a custom data collector. As a result, Intune is not among the supported direct data sources listed in Sentinel.

  • ✓

    Microsoft Defender for Office 365 (formerly Office 365 ATP)

    Why this is correct

    The Microsoft Defender for Office 365 connector (formerly Office 365 ATP) supplies Sentinel with email and collaboration security data, including threat reports such as phishing, malware, and spoofing events. It also brings in mail flow and user-reported messages, which support incident workflows for email-based attacks. This connector is the primary source for Exchange Online threat telemetry.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.