SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Sentinel to centralize security events. You need to ensure that alerts from Microsoft Defender for Cloud are automatically ingested into Sentinel. Which data connector should you enable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Cloud connector
The Microsoft Defender for Cloud connector (formerly Azure Security Center) is specifically designed to ingest alerts and recommendations from Defender for Cloud into Sentinel. The other options are unrelated: Office 365 connector ingests Office logs, Azure Activity logs track Azure resource operations, and DNS connector ingests DNS queries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS connector
Why it's wrong here
The DNS connector in Microsoft Sentinel ingests raw DNS query logs from Windows DNS servers, which is useful for threat hunting, but it is not designed to pull security alerts or recommendations from Defender for Cloud. DNS logs lack the structured incident metadata, severity, and entity information found in Defender for Cloud alerts, so this connector is incorrect for the described scenario.
- ✗
Office 365 connector
Why it's wrong here
The Office 365 connector collects audit logs for Exchange, SharePoint, Teams, and other M365 services via the Office Management API, giving visibility into user and admin activities. It does not integrate with Defender for Cloud's security alert feeds, which focus on workload protections like VMs, storage, and SQL. Therefore, it would not bring the required alerts into Sentinel.
- ✓
Microsoft Defender for Cloud connector
Why this is correct
The Microsoft Defender for Cloud connector is the native data connector that directly imports security alerts and recommendations from Defender for Cloud into Sentinel via its API. This connector populates the SecurityAlert table with structured findings, including severity, status, and associated entities, enabling correlation with other data sources and automated SOAR actions. It is the only connector from the options that is purpose-built for this integration.
- ✗
Azure Activity connector
Why it's wrong here
The Azure Activity connector ingests subscription-level control-plane logs, such as resource creation, role assignments, and ARM operations, from the Azure Activity Log. While valuable for operational auditing and detecting suspicious administrative activity, it does not capture workload security alerts generated by Defender for Cloud, such as those for VM vulnerabilities or network detections. This connector is unrelated to the alert feed required here.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.