Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Your organization is designing a Microsoft Sentinel solution to detect and respond to threats across multi-cloud environments (Azure, AWS, GCP). Which TWO components are essential for this design?

⚠ Common exam trap

A common mix-up: candidates confuse Microsoft Defender for Cloud (a CSPM tool) with a data ingestion mechanism, or assume Azure Policy can enforce log collection across non-Azure clouds, when in fact only purpose-built data connectors can bring external logs into Sentinel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data connectors for AWS and GCP

Option B is correct because Microsoft Sentinel ingests AWS and GCP telemetry through dedicated data connectors (for example, the AWS S3/CloudTrail connector and the GCP Pub/Sub connector), which are the mechanism that brings multi-cloud logs into the Sentinel workspace for correlation and detection. Option E is correct because analytics rules are the Sentinel detection logic that runs scheduled or near-real-time queries against the ingested multi-cloud data to generate incidents and alerts, which is the core of detecting threats across Azure, AWS, and GCP. Option A is not essential here because Azure Policy assignments govern resource compliance and configuration within Azure, not cross-cloud threat detection in Sentinel. Option C is not essential because Microsoft Defender for Cloud primarily provides CSPM/CWPP posture and workload protection for Azure, AWS, and GCP but is not the Sentinel component that ingests and detects on multi-cloud logs. Option D is not essential because Azure Automation accounts are used for runbook orchestration and task automation, not for the core ingestion and detection design of a multi-cloud Sentinel solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Policy assignments

    Why it's wrong here

    Azure Policy is an Azure-native governance service that evaluates compliance of Azure resources against defined policies. It has no data-plane ingestion capability and cannot access or parse log streams from AWS S3 or GCP Cloud Logging, so it cannot serve as a multi-cloud log collector for Microsoft Sentinel. Its role is limited to Azure subscription and resource-group scopes, making it irrelevant for onboarding non-Azure telemetry.

  • ✓

    Data connectors for AWS and GCP

    Why this is correct

    Microsoft Sentinel's data connectors for AWS (using S3 with CloudTrail, VPC Flow Logs, and GuardDuty findings) and for GCP (using Cloud Logging via Pub/Sub) are purpose-built to ingest cloud-native telemetry into the Log Analytics workspace. These connectors are the foundational first step in a multi-cloud design, transforming raw logs into tables that analytics rules and workbooks can query. Without them, none of the subsequent detection or incident response logic has data to operate on, so they are the correct answer.

  • ✗

    Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud is a security posture management and workload protection solution that can onboard AWS and GCP resources and forward security alerts to Sentinel, but it is not the primary mechanism for ingesting raw cloud logs. Its GCP support is limited compared to AWS, and even with multi-cloud connectors, it aggregates security findings rather than streaming all underlying log sources into the Sentinel workspace. Therefore it does not fulfill the requirement for broad multi-cloud log collection that data connectors provide.

  • ✗

    Azure Automation accounts

    Why it's wrong here

    Azure Automation accounts run PowerShell or Python runbooks and manage configuration within Azure, typically for patching, maintenance, or remediation tasks. They lack any built-in log ingestion pipelines or cloud-to-cloud connectors that would feed AWS or GCP telemetry into Sentinel; even custom runbooks would have to duplicate logic that the dedicated data connectors already provide. Since the question asks for the core architectural component, Automation accounts are not the right choice.

  • ✓

    Analytics rules for multi-cloud detection

    Why this is correct

    Analytics rules are necessary to correlate events across Azure, AWS, and GCP and generate security incidents, but they act only on data already resident in the Log Analytics workspace. They cannot bring in external logs; they are queries (typically KQL) that run on schedule over existing tables. Thus they are a complement after ingestion, not the component that makes multi-cloud data available to Sentinel in the first place.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.