Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO actions should you take to ensure that Microsoft Sentinel can detect and respond to threats across your multicloud environment, including AWS and GCP?

⚠ Common exam trap

Test-takers frequently assume enabling a connector alone is sufficient for detection, forgetting that analytics rules are required to define what constitutes a threat; they also mistakenly think Microsoft Defender XDR can directly ingest AWS/GCP logs, when it only handles Microsoft 365 data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create analytics rules in Microsoft Sentinel to detect threats from the ingested multicloud logs.

Analytics rules in Microsoft Sentinel define the conditions under which alerts are generated from ingested data. Without these rules, the raw logs from AWS S3 and GCP Pub/Sub would be stored but not evaluated for threats, rendering detection ineffective. Creating custom or built-in analytics rules is essential to transform ingested multicloud logs into actionable security incidents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Azure Policy to deploy the connectors automatically.

    Why it's wrong here

    Azure Policy is a governance and compliance service that evaluates and enforces rules on Azure resources, and while it can deploy some resources via DeployIfNotExists effects, it cannot directly configure third-party SaaS data connectors. AWS S3 and GCP Pub/Sub connectors require external authentication credentials, bucket/topic configurations, and subscription details that Azure Policy cannot provision or manage. Therefore, even if connectors were automatically deployed, Azure Policy would not make Sentinel detect or analyze threats—it lacks the necessary visibility into analytics rules and alert generation.

  • ✓

    Create analytics rules in Microsoft Sentinel to detect threats from the ingested multicloud logs.

    Why this is correct

    Analytics rules are the core detection mechanism in Microsoft Sentinel; without them, ingested logs remain dormant and never generate alerts or incidents. These rules use Kusto Query Language (KQL) to define detection logic, set alert thresholds, and trigger automated responses when suspicious activity matches. Enabling the AWS S3 and GCP Pub/Sub connectors supplies raw log data, but only analytics rules transform that data into actionable security incidents by performing correlation and pattern matching across the multicloud logs.

  • ✓

    Configure the AWS S3 and GCP Pub/Sub data connectors.

    Why this is correct

    To ingest multicloud logs into Microsoft Sentinel, you must configure the dedicated AWS S3 connector and the GCP Pub/Sub connector. The AWS S3 connector pulls CloudTrail, VPC Flow Logs, and other AWS logs from an S3 bucket, while the GCP Pub/Sub connector receives logs from GCP services via a Pub/Sub subscription. These connectors are purpose-built for their respective cloud ecosystems and handle the necessary authentication, parsing, and normalization into Sentinel's workspace. Without them, no raw AWS or GCP data would be available for analytics rules to process.

  • ✗

    Enable the Microsoft Defender XDR connector for AWS and GCP.

    Why it's wrong here

    The Microsoft Defender XDR connector is designed to ingest alerts and incidents from Microsoft 365 Defender, Defender for Endpoint, Defender for Identity, and Defender for Office 365—it does not ingest raw logs from AWS or GCP. AWS and GCP logs are ingested only through purpose-specific connectors such as the AWS S3 connector or the GCP Pub/Sub connector. Enabling the Defender XDR connector for AWS and GCP is conceptually invalid because these third-party cloud platforms are not integrated into the Microsoft 365 Defender ecosystem as data sources. Furthermore, Defender XDR alerts are endpoint/identity-focused, not multicloud infrastructure logs.

  • ✗

    Create a separate Microsoft Sentinel workspace for each cloud provider.

    Why it's wrong here

    Creating a separate Microsoft Sentinel workspace for each cloud provider fragments your security operations by breaking cross-cloud correlation; a single workspace can aggregate logs from AWS, GCP, and Azure, enabling unified detection and incident response. Separate workspaces also multiply administrative overhead, increase licensing and storage costs, and require you to manage multiple query environments. Microsoft Sentinel is explicitly designed as a SIEM for multicloud visibility, so using one workspace per provider defeats that purpose and makes it harder to identify cloud-to-cloud attack paths.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.