Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Which TWO components are required to enable Microsoft Sentinel to ingest data from Amazon Web Services (AWS) CloudTrail?

⚠ Common exam trap

Many candidates assume an Azure Function or Event Hubs is needed for cross-cloud ingestion, but Sentinel's native AWS connector uses S3 and SQS directly, eliminating the need for intermediary compute or messaging services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An AWS S3 bucket to store CloudTrail logs.

Microsoft Sentinel's AWS CloudTrail connector uses a polling-based architecture in which CloudTrail delivers its log files to an Amazon S3 bucket, so option B (an AWS S3 bucket to store CloudTrail logs) is required as the source location that Sentinel reads from. To know when new log objects arrive, the connector relies on Amazon SQS notifications from that S3 bucket, making option D (an AWS SQS queue to trigger ingestion) the second required component, since the SQS queue signals the connector to pull newly delivered CloudTrail files. Option A is not required because the connector runs as a built-in data connector in Microsoft Sentinel rather than a customer-deployed Azure Function. Option C is not required because no AWS Lambda function is used in the CloudTrail ingestion path. Option E is not required because Event Hubs is used for other connectors (such as CEF or syslog-based sources), not for the AWS CloudTrail S3/SQS polling connector.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An Azure Function to pull logs from AWS.

    Why it's wrong here

    The AWS S3 connector in Microsoft Sentinel does not use Azure Functions. The standard ingestion path relies on AWS-native services—S3 for log storage and SQS for event notification—which Sentinel's connector polls directly. Introducing an Azure Function to pull logs adds unnecessary complexity, operational overhead, and potential for data duplication or missed logs, so it is not a required component.

  • ✓

    An AWS S3 bucket to store CloudTrail logs.

    Why this is correct

    The AWS S3 bucket is the core storage location where AWS CloudTrail writes all of its JSON log files. The Microsoft Sentinel AWS connector is built specifically to read these log objects from the S3 bucket, parse the CloudTrail records, and send them to the Log Analytics workspace. Without this bucket there would be no source for the connector to ingest, making it an essential requirement.

  • ✗

    An AWS Lambda function to process logs.

    Why it's wrong here

    AWS Lambda is not part of the Microsoft Sentinel AWS S3 ingestion pipeline. Instead, S3 event notifications send messages directly to an SQS queue, which the connector subscribes to for new log files. Adding a Lambda function to process logs would introduce an extra hop, additional cost, and a custom processing layer that could corrupt or modify the CloudTrail records before Sentinel parses them, so it is not required.

  • ✓

    An AWS Simple Queue Service (SQS) queue to trigger ingestion.

    Why this is correct

    The SQS queue acts as the notification trigger for the AWS S3 connector in Sentinel. When new CloudTrail log objects arrive, S3 publishes a message to the queue, and the Sentinel connector polls the queue to learn which objects to ingest. Without SQS, the connector would have to rely on inefficient polling of S3, so the queue is required for an event-driven, real-time ingestion flow.

  • ✗

    An Azure Event Hubs namespace to receive logs.

    Why it's wrong here

    Azure Event Hubs is a data ingestion service for Azure-native telemetry such as Azure Activity Logs, diagnostics logs, and Microsoft 365 data. It is not used by the AWS S3 connector, which uses AWS SQS instead. Creating an Event Hubs namespace would not help expose AWS CloudTrail logs to Sentinel and would be an unnecessary Azure resource in this architecture.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.