Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

A company uses Microsoft Defender for Identity (MDI) to monitor on-premises Active Directory. They want to integrate MDI alerts into Microsoft Sentinel. Which data connector should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Identity connector

The Microsoft Defender for Identity connector is the correct choice because it is the purpose-built Microsoft Sentinel data connector that ingests MDI alerts and related entity data directly from the MDI service into the Sentinel workspace, enabling built-in analytics rules and incident creation. The Syslog connector is for forwarding syslog/CEF events from Linux or network devices, not for MDI's native alert stream. The Microsoft Entra ID connector ingests Microsoft Entra ID sign-in and audit logs, not on-premises AD threat alerts from MDI. Windows Security Events via AMA collects Windows event logs from servers, which does not include MDI's correlated identity alerts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Syslog connector

    Why it's wrong here

    The Syslog connector is for ingesting log data from network appliances, firewalls, and other non-Microsoft security tools that emit RFC 3164 or RFC 5424 messages. MDI alerts do not leave your environment via Syslog—they are generated by MDI sensors on domain controllers and are delivered through the Microsoft 365 Defender backend. Therefore, selecting the Syslog connector cannot bring MDI alert data into Sentinel.

  • ✗

    Microsoft Entra ID connector

    Why it's wrong here

    The Microsoft Entra ID (now Microsoft Entra ID) connector ingests Entra ID sign-in logs, audit logs, and provisioning logs into Microsoft Sentinel. MDI detections are not part of those log categories; they are separately produced by the Defender for Identity service based on domain controller and AD signals. This connector is therefore a direct functional mismatch when the requirement is specifically MDI alerts.

  • ✓

    Microsoft Defender for Identity connector

    Why this is correct

    The Microsoft Defender for Identity connector is the dedicated data connector designed to import MDI alerts into Microsoft Sentinel. It leverages the Microsoft 365 Defender data export model, pulling MDI-generated security alerts so they can be correlated with other Sentinel data. This is the only connector in the list whose native purpose is to ingest MDI alert telemetry, making it the correct choice for this scenario.

  • ✗

    Windows Security Events via AMA

    Why it's wrong here

    The Windows Security Events via AMA connector ingests raw Windows Event Log entries—such as Security (Event IDs 4624/4625), System, and custom logs—from servers and endpoints into Sentinel via the Azure Monitor Agent. These are event-level records from individual machines, not MDI detection alerts generated by the Defender for Identity sensor infrastructure. It also requires an agent deployment and data collection rule, which is not an alternative method for pulling MDI alert outputs into Sentinel.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.