SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Which TWO components are required to enable Microsoft Sentinel to ingest data from Amazon Web Services (AWS) CloudTrail?
⚠ Common exam trap
Many candidates assume an Azure Function or Event Hubs is needed for cross-cloud ingestion, but Sentinel's native AWS connector uses S3 and SQS directly, eliminating the need for intermediary compute or messaging services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An AWS S3 bucket to store CloudTrail logs.
Microsoft Sentinel's AWS CloudTrail connector uses a polling-based architecture in which CloudTrail delivers its log files to an Amazon S3 bucket, so option B (an AWS S3 bucket to store CloudTrail logs) is required as the source location that Sentinel reads from. To know when new log objects arrive, the connector relies on Amazon SQS notifications from that S3 bucket, making option D (an AWS SQS queue to trigger ingestion) the second required component, since the SQS queue signals the connector to pull newly delivered CloudTrail files. Option A is not required because the connector runs as a built-in data connector in Microsoft Sentinel rather than a customer-deployed Azure Function. Option C is not required because no AWS Lambda function is used in the CloudTrail ingestion path. Option E is not required because Event Hubs is used for other connectors (such as CEF or syslog-based sources), not for the AWS CloudTrail S3/SQS polling connector.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An Azure Function to pull logs from AWS.
Why it's wrong here
The AWS S3 connector in Microsoft Sentinel does not use Azure Functions. The standard ingestion path relies on AWS-native services—S3 for log storage and SQS for event notification—which Sentinel's connector polls directly. Introducing an Azure Function to pull logs adds unnecessary complexity, operational overhead, and potential for data duplication or missed logs, so it is not a required component.
- ✓
An AWS S3 bucket to store CloudTrail logs.
Why this is correct
The AWS S3 bucket is the core storage location where AWS CloudTrail writes all of its JSON log files. The Microsoft Sentinel AWS connector is built specifically to read these log objects from the S3 bucket, parse the CloudTrail records, and send them to the Log Analytics workspace. Without this bucket there would be no source for the connector to ingest, making it an essential requirement.
- ✗
An AWS Lambda function to process logs.
Why it's wrong here
AWS Lambda is not part of the Microsoft Sentinel AWS S3 ingestion pipeline. Instead, S3 event notifications send messages directly to an SQS queue, which the connector subscribes to for new log files. Adding a Lambda function to process logs would introduce an extra hop, additional cost, and a custom processing layer that could corrupt or modify the CloudTrail records before Sentinel parses them, so it is not required.
- ✓
An AWS Simple Queue Service (SQS) queue to trigger ingestion.
Why this is correct
The SQS queue acts as the notification trigger for the AWS S3 connector in Sentinel. When new CloudTrail log objects arrive, S3 publishes a message to the queue, and the Sentinel connector polls the queue to learn which objects to ingest. Without SQS, the connector would have to rely on inefficient polling of S3, so the queue is required for an event-driven, real-time ingestion flow.
- ✗
An Azure Event Hubs namespace to receive logs.
Why it's wrong here
Azure Event Hubs is a data ingestion service for Azure-native telemetry such as Azure Activity Logs, diagnostics logs, and Microsoft 365 data. It is not used by the AWS S3 connector, which uses AWS SQS instead. Creating an Event Hubs namespace would not help expose AWS CloudTrail logs to Sentinel and would be an unnecessary Azure resource in this architecture.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.