SC-200 Manage a security operations environment Practice Question
Which THREE are valid ways to ingest data into Microsoft Sentinel? (Select three.)
⚠ Common exam trap
Candidates often assume any Microsoft service (like Azure DevOps or Power BI) can be directly connected via a built-in connector, but Sentinel only provides connectors for services that generate security-relevant logs, not for project management or BI analytics tools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configuring Syslog using Azure Monitor Agent (AMA)
The Azure Monitor Agent (AMA) can collect Syslog events from Linux-based sources and forward them to a Log Analytics workspace, which is the underlying data store for Microsoft Sentinel. By configuring a Data Collection Rule (DCR) that specifies the Syslog facility and severity levels, AMA streams these logs into the Syslog table in the workspace, making them available for detection and analysis within Sentinel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configuring Syslog using Azure Monitor Agent (AMA)
Why this is correct
Configuring Syslog using Azure Monitor Agent (AMA) is a fully supported ingestion path in Microsoft Sentinel. AMA runs on Linux virtual machines and uses Data Collection Rules (DCRs) to define which facilities and severities to forward to the Log Analytics workspace that Sentinel monitors. This method replaces the legacy Log Analytics agent, allowing you to collect syslog events from on-premises and cloud Linux servers, and it is a first-party, no-code option in the data connectors gallery.
- ✓
Using the Microsoft Sentinel API to push custom logs
Why this is correct
The Microsoft Sentinel API, specifically the Log Ingestion API, enables you to push custom logs from applications or custom-built collectors into custom tables in the Log Analytics workspace. You must create a custom table and a Data Collection Rule (DCR) to define the schema, then authenticate with Microsoft Entra ID (often using a service principal) to send POST requests to the DCR endpoint. This is a valid, programmatic ingestion method for scenarios where no built-in connector exists.
- ✗
Connecting to Azure DevOps directly
Why it's wrong here
Connecting Azure DevOps directly to Microsoft Sentinel is not supported as a built-in data source. Sentinel's data connectors do not include Azure DevOps, and you cannot simply point Sentinel to an Azure DevOps organization or project to receive work item, build, or release logs. To bring such data into Sentinel, you would need to use an intermediate orchestration mechanism like a Logic App, a Function App, or the Log Ingestion API to pull the data and push it to a custom table.
- ✗
Importing from Power BI datasets
Why it's wrong here
Importing from Power BI datasets is not a valid ingestion method because Power BI is a visualization and analytics platform, not a telemetry source. Sentinel ingests raw logs and events, not pre-aggregated data in analytic models, and there is no built-in data connector that pulls datasets from Power BI into a Log Analytics workspace. Even if you exported data from Power BI and uploaded it as a custom log, that would be a manual workaround, not a direct import mechanism.
- ✓
Using a built-in data connector for Microsoft Entra ID
Why this is correct
Using a built-in data connector for Microsoft Entra ID is a valid and common ingestion path in Sentinel. The Entra ID connector streams sign-in logs, audit logs, and provisioning logs directly into the Log Analytics workspace without requiring any agent or custom code. You simply enable the connector in Sentinel and configure the diagnostic settings in Microsoft Entra ID to route those logs to the workspace, making it a quick, natively integrated way to monitor identity-related activity.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.