Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your company uses Microsoft Sentinel as a SIEM. You need to ensure that all Azure subscription activity logs are ingested into Sentinel. What is the most efficient way to configure this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the 'Azure Activity' data connector in Sentinel.

The Azure Activity data connector is specifically designed to ingest subscription-level activity logs into Microsoft Sentinel. Option A is incorrect because although diagnostic settings can send activity logs to a Log Analytics workspace, Sentinel requires the data connector to properly collect and correlate the data. Option B is incorrect because an Azure Logic App would be an inefficient custom solution when a built-in connector exists. Option D is incorrect because manually exporting to a storage account is not efficient or automated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure diagnostic settings on the subscription to send logs to a Log Analytics workspace.

    Why it's wrong here

    Configuring subscription diagnostic settings to stream Activity Logs into a Log Analytics workspace does send data to the workspace that Sentinel uses as its data store, but this alone does not establish Sentinel's ingest pipeline. The Azure Activity data connector must be enabled to create the properly normalized AzureActivity table, configure the Sentinel connector's schema mapping, and activate the built-in analytics rules that rely on that table. Without enabling the connector, the data arrives in a generic workspace but Sentinel cannot fully index, alert, and hunt on it as intended.

  • ✗

    Create an Azure Logic App to periodically pull activity logs.

    Why it's wrong here

    Building an Azure Logic App to poll and pull activity logs would require custom code, API calls, and error handling, resulting in a brittle and inefficient ingestion path with significant latency. Sentinel provides a native managed connector for Azure Activity, which continuously streams the logs in near real-time without needing any manual orchestration. This custom approach also incurs unnecessary compute costs, requires ongoing maintenance, and doesn't integrate with Sentinel's built-in connectors, alerting, or workbook templates.

  • ✓

    Enable the 'Azure Activity' data connector in Sentinel.

    Why this is correct

    Enabling the Azure Activity data connector in Microsoft Sentinel automatically configures the required diagnostic settings at the subscription level and begins near-real-time streaming of control-plane events into the AzureActivity table within your Sentinel workspace. It is the supported, turnkey method for this integration: the connector handles schema mapping, enrichment, and provides out-of-the-box detection rules, workbooks, and hunting queries. Once enabled, all operations such as resource creation, policy changes, and security alerts are immediately visible in Sentinel.

  • ✗

    Manually export activity logs to a storage account and connect to Sentinel.

    Why it's wrong here

    Manually exporting activity logs to a storage account (for example, via scheduled PowerShell scripts) and later pointing Sentinel at that storage is operationally burdensome, prone to gaps, and produces data delay that defeats real-time monitoring. Even if you use the Azure Diagnostics connector to ingest from the storage account, you must maintain blob integrity, manage timestamp parsing, and handle overwrite/append logic. The native connector streams directly from the source, eliminating this intermediate hop and ensuring continuous, reliable, low-latency availability for security analysis.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.