Courseiva
Perform threat hunting →mediumMultiple Select

SC-200 Microsoft Sentinel data sources Practice Question

Which THREE of the following are valid sources of data that a threat hunter can use in Microsoft Sentinel for hunting? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID audit logs

Microsoft Sentinel ingests Microsoft Entra ID audit logs through the Microsoft Entra ID (now Entra ID) data connector, which records sign-in and directory activity and is a legitimate hunting source, so option A is correct. Microsoft 365 audit logs are collected via the Office 365 data connector (using the Management Activity API) and provide Exchange, SharePoint, Teams, and general audit events usable for hunting, making option D correct. AWS CloudTrail logs are supported through the Amazon Web Services S3/CloudTrail connector, which pulls API activity into Sentinel for cross-cloud hunting, so option E is correct. Azure Cost Management data (option B) is billing and cost-analysis telemetry, not security event data ingested as a hunting table in Sentinel, and Azure DevOps pipelines (option C) are CI/CD build/release processes rather than a native Sentinel hunting data source, so neither belongs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra ID audit logs

    Why this is correct

    Microsoft Entra ID audit logs record sign-in and directory change activity, and Microsoft Sentinel ingests them through the Entra ID data connector. They surface authentication anomalies and privilege changes, giving threat hunters a native identity-based data source for correlating suspicious account behaviour across the environment.

  • ✗

    Azure Cost Management data

    Why it's wrong here

    Cost Management records billing and consumption, containing no security telemetry such as sign-in, process or network events. It tempts because it is an Azure-native data source surfaced in the portal, but hunting requires log data, not spend metrics.

  • ✗

    Azure DevOps pipelines

    Why it's wrong here

    Azure DevOps pipelines hold build and deployment records, not the endpoint, identity or network telemetry hunting queries consume. It tempts because pipeline logs can reveal supply-chain compromise, but that requires separate ingestion, not native Sentinel hunting tables.

  • ✓

    Microsoft 365 audit logs

    Why this is correct

    Microsoft 365 audit logs flow into Microsoft Sentinel through the Office 365 connector, supplying unified audit records of user and admin activity. Threat hunters query these logs alongside other sources to investigate suspicious behaviour, making them a valid hunting data source.

  • ✓

    AWS CloudTrail logs

    Why this is correct

    AWS CloudTrail logs capture API activity in Amazon Web Services accounts, and Microsoft Sentinel's AWS CloudTrail connector ingests them into the workspace. This lets threat hunters correlate cloud control-plane actions with Microsoft telemetry, satisfying the requirement for valid multi-cloud hunting data sources.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.