Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Which THREE are valid sources for ingesting data into Microsoft Sentinel? (Choose three.)

⚠ Common exam trap

Many candidates assume any popular cloud service (like Adobe Analytics or Google BigQuery) can be a data source for Sentinel, but Microsoft only provides built-in connectors for specific security-relevant sources, and these two are not among them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is a valid data source for Microsoft Sentinel because Sentinel supports ingesting AWS service logs via the AWS CloudTrail data connector. This connector uses the AWS S3 bucket to collect CloudTrail logs, which are then pulled into Sentinel for analysis. This allows organizations to monitor and detect threats across their AWS environment alongside other cloud and on-premises data sources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is a valid source because Microsoft Sentinel provides a native data connector that ingests CloudTrail management and data plane logs. By leveraging an S3 bucket and an SQS queue, Sentinel pulls API activity from AWS, allowing security teams to detect misconfigurations, credential abuse, and unauthorized access across AWS accounts.

  • ✓

    Microsoft 365 Defender

    Why this is correct

    Microsoft 365 Defender is a valid source because Sentinel includes a built-in connector that ingests alerts and incidents from Defender for Endpoint, Defender for Office 365, and Defender for Identity. This integration streams high-fidelity security alerts directly into Sentinel, enabling correlated hunting and automated response across the Microsoft 365 ecosystem.

  • ✗

    Adobe Analytics

    Why it's wrong here

    Adobe Analytics is not a valid source because Sentinel does not offer a built-in data connector for this product. While you could theoretically ingest its data via a custom API-based function app or the HTTP Data Collector API, that would require custom development and is not a supported native source for seamless, out-of-the-box data ingestion.

  • ✓

    Azure Activity log

    Why this is correct

    Azure Activity log is a valid source because Sentinel provides a first-party connector that streams subscription-level operational events, such as resource creation, policy changes, and administrative actions. This source gives security analysts visibility into the Azure control plane, and it can be enabled directly from the Sentinel connector gallery without additional infrastructure.

  • ✗

    Google BigQuery

    Why it's wrong here

    Google BigQuery is not a valid source because Sentinel lacks a native connector for this cloud data warehouse. Alternative approaches, like using Azure Data Factory to export BigQuery tables into Azure Blob Storage and then ingesting via a custom connector, are convoluted and not considered standard data connectors, making it unsuitable as a straightforward source for Sentinel.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.