SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Which THREE are valid sources for ingesting data into Microsoft Sentinel? (Choose three.)
⚠ Common exam trap
Many candidates assume any popular cloud service (like Adobe Analytics or Google BigQuery) can be a data source for Sentinel, but Microsoft only provides built-in connectors for specific security-relevant sources, and these two are not among them.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is a valid data source for Microsoft Sentinel because Sentinel supports ingesting AWS service logs via the AWS CloudTrail data connector. This connector uses the AWS S3 bucket to collect CloudTrail logs, which are then pulled into Sentinel for analysis. This allows organizations to monitor and detect threats across their AWS environment alongside other cloud and on-premises data sources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is a valid source because Microsoft Sentinel provides a native data connector that ingests CloudTrail management and data plane logs. By leveraging an S3 bucket and an SQS queue, Sentinel pulls API activity from AWS, allowing security teams to detect misconfigurations, credential abuse, and unauthorized access across AWS accounts.
- ✓
Microsoft 365 Defender
Why this is correct
Microsoft 365 Defender is a valid source because Sentinel includes a built-in connector that ingests alerts and incidents from Defender for Endpoint, Defender for Office 365, and Defender for Identity. This integration streams high-fidelity security alerts directly into Sentinel, enabling correlated hunting and automated response across the Microsoft 365 ecosystem.
- ✗
Adobe Analytics
Why it's wrong here
Adobe Analytics is not a valid source because Sentinel does not offer a built-in data connector for this product. While you could theoretically ingest its data via a custom API-based function app or the HTTP Data Collector API, that would require custom development and is not a supported native source for seamless, out-of-the-box data ingestion.
- ✓
Azure Activity log
Why this is correct
Azure Activity log is a valid source because Sentinel provides a first-party connector that streams subscription-level operational events, such as resource creation, policy changes, and administrative actions. This source gives security analysts visibility into the Azure control plane, and it can be enabled directly from the Sentinel connector gallery without additional infrastructure.
- ✗
Google BigQuery
Why it's wrong here
Google BigQuery is not a valid source because Sentinel lacks a native connector for this cloud data warehouse. Alternative approaches, like using Azure Data Factory to export BigQuery tables into Azure Blob Storage and then ingesting via a custom connector, are convoluted and not considered standard data connectors, making it unsuitable as a straightforward source for Sentinel.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.