Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Your organization is using Microsoft Sentinel for security information and event management (SIEM). You need to ensure that data from Azure Activity Logs is ingested into Sentinel. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Connect Azure Activity Logs via the Microsoft Sentinel data connector

You can connect Azure Activity Logs as a data connector in Microsoft Sentinel. Option A is wrong because Log Analytics workspace is the underlying storage, but the connection is made via data connectors. Option B is wrong because Azure Policy can enforce configuration but not directly ingest logs. Option C is wrong because Azure Monitor is a broader service; the specific connector is needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a Log Analytics workspace to collect Activity Logs

    Why it's wrong here

    A Log Analytics workspace is the destination store for logs, not the collection mechanism. Simply configuring the workspace to accept Activity Logs (e.g., via diagnostic settings) does not bring them into Microsoft Sentinel's analytical tables, nor does it create the required Sentinel data connector relationship. The Activity Log stream must be explicitly connected through the Microsoft Sentinel data connector to appear in the Sentinel workspace and be available for analytics rules.

  • ✗

    Use Azure Policy to stream Activity Logs to Sentinel

    Why it's wrong here

    Azure Policy is a governance and compliance service that evaluates resource configurations; it does not have a data-plane mechanism to continuously forward or stream tenant-level Activity Logs into Sentinel. Although a policy definition can audit or even deploy a diagnostic setting for a resource, it cannot itself ingest logs into the Sentinel workspace. Only the Microsoft Sentinel Activity Logs data connector establishes the streaming pipeline for those platform logs.

  • ✗

    Enable Azure Monitor to forward Activity Logs to Sentinel

    Why it's wrong here

    Azure Monitor is the broader telemetry platform that transports and stores platform logs, but simply enabling Azure Monitor does not create the Sentinel-side integration needed for ingestion. Without going to Sentinel's Data connectors pane and enabling the Azure Activity log connector, the logs remain in the Log Analytics workspace but are not exposed to Sentinel's SIEM features like analytics rules and UEBA. The connector is the specific object that wires the Azure Monitor stream into Sentinel's `AzureActivity` table.

  • ✓

    Connect Azure Activity Logs via the Microsoft Sentinel data connector

    Why this is correct

    The Microsoft Sentinel data connector for Azure Activity is the authoritative, supported integration for ingesting control-plane events into the Sentinel workspace. This connector provisions the necessary data collector and maps the stream to the `AzureActivity` table, enabling analytics, hunting, and alerting. It appears in the Data connectors blade and is the standard first step when onboarding tenant-level logs.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.