SC-200 Manage a security operations environment Practice Question
Which TWO actions should you take to ensure that Microsoft Sentinel can detect and respond to threats across your multicloud environment, including AWS and GCP?
⚠ Common exam trap
Test-takers frequently assume enabling a connector alone is sufficient for detection, forgetting that analytics rules are required to define what constitutes a threat; they also mistakenly think Microsoft Defender XDR can directly ingest AWS/GCP logs, when it only handles Microsoft 365 data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create analytics rules in Microsoft Sentinel to detect threats from the ingested multicloud logs.
Analytics rules in Microsoft Sentinel define the conditions under which alerts are generated from ingested data. Without these rules, the raw logs from AWS S3 and GCP Pub/Sub would be stored but not evaluated for threats, rendering detection ineffective. Creating custom or built-in analytics rules is essential to transform ingested multicloud logs into actionable security incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Azure Policy to deploy the connectors automatically.
Why it's wrong here
Azure Policy is a governance and compliance service that evaluates and enforces rules on Azure resources, and while it can deploy some resources via DeployIfNotExists effects, it cannot directly configure third-party SaaS data connectors. AWS S3 and GCP Pub/Sub connectors require external authentication credentials, bucket/topic configurations, and subscription details that Azure Policy cannot provision or manage. Therefore, even if connectors were automatically deployed, Azure Policy would not make Sentinel detect or analyze threats—it lacks the necessary visibility into analytics rules and alert generation.
- ✓
Create analytics rules in Microsoft Sentinel to detect threats from the ingested multicloud logs.
Why this is correct
Analytics rules are the core detection mechanism in Microsoft Sentinel; without them, ingested logs remain dormant and never generate alerts or incidents. These rules use Kusto Query Language (KQL) to define detection logic, set alert thresholds, and trigger automated responses when suspicious activity matches. Enabling the AWS S3 and GCP Pub/Sub connectors supplies raw log data, but only analytics rules transform that data into actionable security incidents by performing correlation and pattern matching across the multicloud logs.
- ✓
Configure the AWS S3 and GCP Pub/Sub data connectors.
Why this is correct
To ingest multicloud logs into Microsoft Sentinel, you must configure the dedicated AWS S3 connector and the GCP Pub/Sub connector. The AWS S3 connector pulls CloudTrail, VPC Flow Logs, and other AWS logs from an S3 bucket, while the GCP Pub/Sub connector receives logs from GCP services via a Pub/Sub subscription. These connectors are purpose-built for their respective cloud ecosystems and handle the necessary authentication, parsing, and normalization into Sentinel's workspace. Without them, no raw AWS or GCP data would be available for analytics rules to process.
- ✗
Enable the Microsoft Defender XDR connector for AWS and GCP.
Why it's wrong here
The Microsoft Defender XDR connector is designed to ingest alerts and incidents from Microsoft 365 Defender, Defender for Endpoint, Defender for Identity, and Defender for Office 365—it does not ingest raw logs from AWS or GCP. AWS and GCP logs are ingested only through purpose-specific connectors such as the AWS S3 connector or the GCP Pub/Sub connector. Enabling the Defender XDR connector for AWS and GCP is conceptually invalid because these third-party cloud platforms are not integrated into the Microsoft 365 Defender ecosystem as data sources. Furthermore, Defender XDR alerts are endpoint/identity-focused, not multicloud infrastructure logs.
- ✗
Create a separate Microsoft Sentinel workspace for each cloud provider.
Why it's wrong here
Creating a separate Microsoft Sentinel workspace for each cloud provider fragments your security operations by breaking cross-cloud correlation; a single workspace can aggregate logs from AWS, GCP, and Azure, enabling unified detection and incident response. Separate workspaces also multiply administrative overhead, increase licensing and storage costs, and require you to manage multiple query environments. Microsoft Sentinel is explicitly designed as a SIEM for multicloud visibility, so using one workspace per provider defeats that purpose and makes it harder to identify cloud-to-cloud attack paths.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.