Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO are supported data sources for Microsoft Sentinel?

⚠ Common exam trap

It's easy for candidates to assume any syslog source (like syslog-ng) is directly supported, but Microsoft Sentinel only supports syslog via the Linux agent or AMA, not the syslog-ng daemon itself as a distinct data source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID audit logs

Microsoft Entra ID audit logs (Option C) are a native data source for Microsoft Sentinel because Sentinel is built on Azure Monitor Logs and directly ingests Entra ID (formerly Azure AD) diagnostic settings via the Azure portal or API. This integration requires no additional connectors or agents, as Entra ID audit logs are automatically forwarded to a Log Analytics workspace when configured under 'Diagnostic settings' in the Entra ID blade.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Google Cloud VPC Flow Logs

    Why it's wrong here

    Google Cloud VPC Flow Logs are not a natively supported data source in Microsoft Sentinel. Sentinel provides built-in connectors for AWS CloudTrail and Azure resources, but no first-party Google Cloud Platform (GCP) connector exists; ingesting GCP VPC Flow Logs would require a custom mechanism such as a Function App or third-party SIEM forwarding. Therefore, this option is incorrect as a supported source.

  • ✗

    Windows Server 2008 event logs

    Why it's wrong here

    Windows Server 2008 event logs are not a supported data source because Windows Server 2008 reached end of extended support on January 14, 2020. Sentinel's Windows event-log connectors require a supported operating system and a compatible agent (the Log Analytics agent or Azure Monitor Agent), and Microsoft no longer provides support or security updates for this legacy OS. Thus, this option is incorrect.

  • ✓

    Microsoft Entra ID audit logs

    Why this is correct

    Microsoft Entra ID audit logs are a correct, natively supported data source for Microsoft Sentinel. Sentinel's Microsoft Entra ID connector (formerly Azure AD) ingests sign-in logs, audit logs, and provisioning logs into the workspace for identity-based detection and investigation. This connector is first-party and uses the Microsoft Graph API or diagnostic settings, making it a standard supported source.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is a correct, natively supported data source for Microsoft Sentinel. The Amazon Web Services connector, which can be configured with an AWS IAM role, collects CloudTrail management and data event logs from an S3 or CloudWatch Logs bucket into Sentinel. This is a first-party, supported integration that enables cloud-account security monitoring.

  • ✗

    On-premises syslog-ng

    Why it's wrong here

    On-premises syslog-ng is not a specifically supported data source in Sentinel's documented connector list; the built-in Syslog connector expects standard syslog protocol (RFC 3164/5424) from devices or a syslog server, not the syslog-ng application itself. You could potentially forward syslog-ng output to the Sentinel syslog collector, but this is an indirect forwarding method and lacks a dedicated native connector, so the option as written is incorrect.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.