SC-200 Microsoft Sentinel data sources Practice Question
Which THREE of the following are valid sources of data that a threat hunter can use in Microsoft Sentinel for hunting? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID audit logs
Microsoft Sentinel ingests Microsoft Entra ID audit logs through the Microsoft Entra ID (now Entra ID) data connector, which records sign-in and directory activity and is a legitimate hunting source, so option A is correct. Microsoft 365 audit logs are collected via the Office 365 data connector (using the Management Activity API) and provide Exchange, SharePoint, Teams, and general audit events usable for hunting, making option D correct. AWS CloudTrail logs are supported through the Amazon Web Services S3/CloudTrail connector, which pulls API activity into Sentinel for cross-cloud hunting, so option E is correct. Azure Cost Management data (option B) is billing and cost-analysis telemetry, not security event data ingested as a hunting table in Sentinel, and Azure DevOps pipelines (option C) are CI/CD build/release processes rather than a native Sentinel hunting data source, so neither belongs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID audit logs
Why this is correct
Microsoft Entra ID audit logs record sign-in and directory change activity, and Microsoft Sentinel ingests them through the Entra ID data connector. They surface authentication anomalies and privilege changes, giving threat hunters a native identity-based data source for correlating suspicious account behaviour across the environment.
- ✗
Azure Cost Management data
Why it's wrong here
Cost Management records billing and consumption, containing no security telemetry such as sign-in, process or network events. It tempts because it is an Azure-native data source surfaced in the portal, but hunting requires log data, not spend metrics.
- ✗
Azure DevOps pipelines
Why it's wrong here
Azure DevOps pipelines hold build and deployment records, not the endpoint, identity or network telemetry hunting queries consume. It tempts because pipeline logs can reveal supply-chain compromise, but that requires separate ingestion, not native Sentinel hunting tables.
- ✓
Microsoft 365 audit logs
Why this is correct
Microsoft 365 audit logs flow into Microsoft Sentinel through the Office 365 connector, supplying unified audit records of user and admin activity. Threat hunters query these logs alongside other sources to investigate suspicious behaviour, making them a valid hunting data source.
- ✓
AWS CloudTrail logs
Why this is correct
AWS CloudTrail logs capture API activity in Amazon Web Services accounts, and Microsoft Sentinel's AWS CloudTrail connector ingests them into the workspace. This lets threat hunters correlate cloud control-plane actions with Microsoft telemetry, satisfying the requirement for valid multi-cloud hunting data sources.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.