SC-200 Manage a security operations environment Practice Question
Which TWO data connectors are available in Microsoft Sentinel to ingest data from Microsoft 365 services?
⚠ Common exam trap
Many candidates confuse the legacy name 'Microsoft Entra ID' with the current product name 'Microsoft Entra ID', and may also mistakenly think Microsoft Defender for Cloud is a data source for M365 services rather than a security solution for cloud workloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID
Microsoft Entra ID (formerly Azure Active Directory) is a correct data connector because it ingests sign-in logs, audit logs, and provisioning events from Microsoft's identity service into Microsoft Sentinel. This connector uses the Microsoft Graph API to pull identity-related telemetry, which is essential for monitoring authentication anomalies and privilege escalation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID
Why it's wrong here
The Microsoft Entra ID connector is the legacy name for the identity log integration in Microsoft Sentinel. Microsoft has renamed this connector to Microsoft Entra ID, and the Sentinel UI now lists it under the new name. Choosing the old name would not accurately identify the available connector, even though the underlying data source is the same.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is a cloud security posture management and workload protection solution that produces security alerts and recommendations, not a data connector itself. Sentinel can ingest those alerts through a separate connector, but Defender for Cloud is not a native Microsoft 365 log source. It does not stream user sign-in or activity logs for Office services.
- ✗
Amazon Web Services
Why it's wrong here
Amazon Web Services is a third-party cloud platform whose logs are ingested through AWS-specific connectors such as CloudTrail, not through the Microsoft 365 bridge in Sentinel. While these connectors are valid for AWS environments, they do not bring Microsoft identity or productivity data into Sentinel. Therefore AWS is not one of the two connectors relevant to Microsoft 365 services.
- ✓
Microsoft Entra ID
Why this is correct
Microsoft Entra ID is a correct connector because it ingests sign-in logs (including interactive and non-interactive sign-ins) and audit logs from Microsoft Entra ID into Microsoft Sentinel. This data is essential for identity-based threat detection and investigation, allowing analysts to trace authentication attempts and directory changes.
- ✓
Office 365
Why this is correct
Office 365 is a correct connector because it pulls unified audit logs from Exchange Online, SharePoint Online, Microsoft Teams, and other Office 365 workloads. This connector provides visibility into user activity, file access, and collaboration events, making it a foundational source for productivity-related security monitoring.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.