SC-100 Practice Question: Design security solutions for applications and data
Your organization is using Microsoft Sentinel for security operations. Which THREE data sources can be connected to Microsoft Sentinel out of the box? (Choose THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID (now Microsoft Entra ID)
Options A (Microsoft Entra ID/Entra ID), B (AWS CloudTrail), and D (Microsoft 365 Defender) are all supported out-of-the-box data connectors in Microsoft Sentinel. Option C (Azure DevOps) is not a built-in connector; it requires a custom API or solution. Option E (Power BI) is not a data source connector for Sentinel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID (now Microsoft Entra ID)
Why this is correct
Microsoft Sentinel has a built-in data connector for Microsoft Entra ID (now Microsoft Entra ID) that streams sign-in logs and audit logs into the SigninLogs and AuditLogs tables. This connector is a first-party, low-latency ingestion path for identity telemetry, enabling detection of risky sign-ins, MFA failures, and privilege escalation. Because identity is a primary attack surface, this connector is a standard and correct choice for Sentinel data sources.
- ✓
Amazon Web Services (AWS) CloudTrail
Why this is correct
The Azure Sentinel AWS connector ingests CloudTrail management and data events from Amazon Simple Storage Service (S3) or through a dedicated Event Hub. It is a native, certified connector that populates the AWSCloudTrail table, giving investigators cross-cloud visibility into AWS API activity, IAM changes, and unauthorized resource access. This makes AWS CloudTrail a valid, commonly used data source for multi-cloud security monitoring in Sentinel.
- ✗
Azure DevOps
Why it's wrong here
Azure DevOps is a software collaboration suite for source control, CI/CD pipelines, and work tracking; it is not a telemetry source for security events. As a result, Sentinel provides no built-in data connector for Azure DevOps, and any integration would require a custom HTTP Data Collector API or a Logic App workaround. Since the question asks for supported data sources via standard connectors, Azure DevOps is not a correct answer.
- ✓
Microsoft 365 Defender
Why this is correct
Sentinel’s Microsoft 365 Defender connector pulls in alerts and raw hunting events from Defender for Endpoint, Office 365, Identity, and Cloud Apps. Incidents are surfaced directly into the SecurityIncident table, while advanced hunting data lands in dedicated tables, allowing correlation across the entire XDR suite. This connector is a core component of a Microsoft-centric SecOps strategy, offering seamless integration with the M365 security stack.
- ✗
Power BI
Why it's wrong here
Power BI is a business intelligence and reporting service, not an endpoint, server, or application that produces security event logs. Sentinel has no native data connector for Power BI, and the service is designed for visualizing data rather than acting as a source of security telemetry. Trying to treat Power BI as a Sentinel data source would misrepresent both products and is therefore not a valid choice.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.