SC-100 Practice Question: Design solutions that align with security best practices and priorities
Your organization is designing a Microsoft Sentinel solution to detect and respond to threats across multi-cloud environments (Azure, AWS, GCP). Which TWO components are essential for this design?
⚠ Common exam trap
A common mix-up: candidates confuse Microsoft Defender for Cloud (a CSPM tool) with a data ingestion mechanism, or assume Azure Policy can enforce log collection across non-Azure clouds, when in fact only purpose-built data connectors can bring external logs into Sentinel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data connectors for AWS and GCP
Option B is correct because Microsoft Sentinel ingests AWS and GCP telemetry through dedicated data connectors (for example, the AWS S3/CloudTrail connector and the GCP Pub/Sub connector), which are the mechanism that brings multi-cloud logs into the Sentinel workspace for correlation and detection. Option E is correct because analytics rules are the Sentinel detection logic that runs scheduled or near-real-time queries against the ingested multi-cloud data to generate incidents and alerts, which is the core of detecting threats across Azure, AWS, and GCP. Option A is not essential here because Azure Policy assignments govern resource compliance and configuration within Azure, not cross-cloud threat detection in Sentinel. Option C is not essential because Microsoft Defender for Cloud primarily provides CSPM/CWPP posture and workload protection for Azure, AWS, and GCP but is not the Sentinel component that ingests and detects on multi-cloud logs. Option D is not essential because Azure Automation accounts are used for runbook orchestration and task automation, not for the core ingestion and detection design of a multi-cloud Sentinel solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Policy assignments
Why it's wrong here
Azure Policy is an Azure-native governance service that evaluates compliance of Azure resources against defined policies. It has no data-plane ingestion capability and cannot access or parse log streams from AWS S3 or GCP Cloud Logging, so it cannot serve as a multi-cloud log collector for Microsoft Sentinel. Its role is limited to Azure subscription and resource-group scopes, making it irrelevant for onboarding non-Azure telemetry.
- ✓
Data connectors for AWS and GCP
Why this is correct
Microsoft Sentinel's data connectors for AWS (using S3 with CloudTrail, VPC Flow Logs, and GuardDuty findings) and for GCP (using Cloud Logging via Pub/Sub) are purpose-built to ingest cloud-native telemetry into the Log Analytics workspace. These connectors are the foundational first step in a multi-cloud design, transforming raw logs into tables that analytics rules and workbooks can query. Without them, none of the subsequent detection or incident response logic has data to operate on, so they are the correct answer.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is a security posture management and workload protection solution that can onboard AWS and GCP resources and forward security alerts to Sentinel, but it is not the primary mechanism for ingesting raw cloud logs. Its GCP support is limited compared to AWS, and even with multi-cloud connectors, it aggregates security findings rather than streaming all underlying log sources into the Sentinel workspace. Therefore it does not fulfill the requirement for broad multi-cloud log collection that data connectors provide.
- ✗
Azure Automation accounts
Why it's wrong here
Azure Automation accounts run PowerShell or Python runbooks and manage configuration within Azure, typically for patching, maintenance, or remediation tasks. They lack any built-in log ingestion pipelines or cloud-to-cloud connectors that would feed AWS or GCP telemetry into Sentinel; even custom runbooks would have to duplicate logic that the dedicated data connectors already provide. Since the question asks for the core architectural component, Automation accounts are not the right choice.
- ✓
Analytics rules for multi-cloud detection
Why this is correct
Analytics rules are necessary to correlate events across Azure, AWS, and GCP and generate security incidents, but they act only on data already resident in the Log Analytics workspace. They cannot bring in external logs; they are queries (typically KQL) that run on schedule over existing tables. Thus they are a complement after ingestion, not the component that makes multi-cloud data available to Sentinel in the first place.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.