Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Your organization uses Microsoft Sentinel to centralize security logs from multiple clouds. They need to ensure that logs from Amazon Web Services (AWS) are ingested and analyzed for threats. Which connector should you implement?

⚠ Common exam trap

A common mix-up: candidates confuse Microsoft Defender for Cloud (a security posture tool) with a log ingestion connector, or assume Azure Event Hubs is the default streaming solution for all external logs, overlooking the purpose-built AWS S3 connector that handles the specific S3-to-Sentinel pipeline.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS S3 connector

The AWS S3 connector is the correct choice because it is the native Microsoft Sentinel data connector designed specifically to ingest AWS CloudTrail logs (and other AWS service logs) from an S3 bucket. It uses an AWS Simple Queue Service (SQS) to poll for new log files, then streams them into Sentinel for analysis, enabling threat detection across multi-cloud environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud, while it offers multi-cloud security posture management and can recommend hardening for AWS workloads, is not a log-ingestion connector. It does not read CloudTrail objects from S3 buckets; instead it relies on Azure Arc and API-based assessments to produce security findings. Those findings may be pushed to Sentinel as alerts, but they are not raw AWS activity logs, so this option cannot fulfill the requirement to centralize CloudTrail telemetry.

  • ✗

    Azure Monitor Agent

    Why it's wrong here

    Azure Monitor Agent (AMA) is an agent-based collector designed to run on Azure VMs and Arc-enabled servers, gathering guest OS events and performance counters into a Log Analytics workspace. It has no capability to authenticate to an AWS S3 bucket, pull object metadata, or parse CloudTrail JSON logs. Its data path is from an agent to Azure, not from AWS APIs to Azure, so it is entirely unsuitable for ingesting AWS CloudTrail logs into Sentinel.

  • ✓

    AWS S3 connector

    Why this is correct

    The AWS S3 connector is the correct native Microsoft Sentinel data connector for ingesting AWS CloudTrail logs. It connects to a configured S3 bucket that receives CloudTrail events and optionally uses SQS for near-real-time notifications, then normalizes the JSON records into the AWSCloudTrail table in Log Analytics. This is the standard architectural pattern for centralizing AWS activity monitoring in Sentinel, and it directly satisfies the organization's requirement.

  • ✗

    Azure Event Hubs

    Why it's wrong here

    Azure Event Hubs is a scalable streaming platform and event ingestion pipeline, frequently used to ingest telemetry or log data from many sources before routing to consumers like Sentinel. However, it is not a built-in, point-and-click connector for AWS CloudTrail; no native Sentinel data connector named 'Event Hubs' exists for AWS logs. While an organization could build a custom pipeline that forwards AWS logs to Event Hubs and then to Sentinel, that would be an intermediate hop, not the direct connector this question asks about.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.