Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO data connectors can be used to ingest Microsoft 365 audit logs into Microsoft Sentinel? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse the Microsoft 365 Defender connector with the Office 365 connector, thinking they are redundant, or they mistakenly select the Microsoft Entra ID connector because they assume sign-in logs are part of Microsoft 365 audit logs, when in fact the Microsoft Entra ID connector only captures Microsoft Entra ID-specific events, not the full Microsoft 365 audit log.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft 365 Defender connector.

The Microsoft 365 Defender connector (Option B) ingests unified audit logs from Microsoft 365 Defender, which includes security-related events from Microsoft 365 services. The Office 365 connector (Option C) directly ingests audit logs from Exchange Online, SharePoint Online, and Microsoft Teams, which are part of the Microsoft 365 audit log. Both connectors are designed to bring Microsoft 365 audit log data into Microsoft Sentinel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Cloud Apps connector.

    Why it's wrong here

    This connector focuses on cloud app discovery, shadow IT, and app governance signals, providing visibility into SaaS application usage. It does not ingest the Microsoft 365 unified audit log, which is the central log for all user and admin activity across Exchange, SharePoint, and Teams. The audit log is separate from the app-provided activity data, so selecting this connector would not satisfy the requirement to ingest Microsoft 365 audit logs.

  • ✓

    Microsoft 365 Defender connector.

    Why this is correct

    This connector is a valid choice because it ingests unified audit logs from Microsoft 365, along with alerts and incidents from the Microsoft 365 Defender suite. It allows you to collect audit records related to user actions such as mailbox access, file shares, and Teams messages, which are critical for security investigations. By integrating with Microsoft 365 Defender, the connector provides a streamlined way to bring these logs into your SIEM, making it one of the two correct answers.

  • ✓

    Office 365 connector (Exchange, SharePoint, Teams).

    Why this is correct

    This is the classic and most direct connector for ingesting Microsoft 365 audit logs, specifically from Exchange, SharePoint, and Teams. It leverages the unified audit log to capture events like email activity, file access, and team messages, and these are delivered to your workspace seamlessly. Its scope precisely covers the core Microsoft 365 services, making it the other correct answer for audit log ingestion.

  • ✗

    Azure Activity connector.

    Why it's wrong here

    This connector is designed for Azure platform-level events such as resource creation, configuration changes, and subscription-level occurrences. These are Azure Resource Manager operations, not user-level audit events from Microsoft 365 services like Exchange or SharePoint. Since the requirement is specifically for Microsoft 365 audit logs, the Azure Activity connector does not provide the needed data.

  • ✗

    Microsoft Entra ID connector (sign-in logs).

    Why it's wrong here

    The Microsoft Entra ID connector ingests sign-in logs and Microsoft Entra ID audit logs for directory activities like user management and authentication. While these are related to identity, they are not the same as Microsoft 365 workload audit logs generated by user actions in Office 365 apps. Sign-in logs focus on authentication events, not the content interactions and administrative changes recorded in the unified audit log, so this connector cannot fulfill the request.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.