SC-200 Manage a security operations environment Practice Question
Which TWO data sources are natively supported by Microsoft Sentinel for ingesting security events? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse 'natively supported' with 'available via a connector in the content hub,' but Microsoft Sentinel defines native support as built-in data connectors that require no additional custom code or third-party services, excluding connectors that rely on Azure Functions or partner solutions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Security Events
Windows Security Events are natively supported by Microsoft Sentinel via the Windows Security Events via AMA connector or the legacy Log Analytics agent. This connector ingests security event logs (e.g., Event ID 4625 for failed logons) directly into Sentinel without requiring a third-party parser or custom data connector. Azure Activity Logs are also natively supported through the Azure Activity connector, which streams subscription-level operational events (e.g., resource creation, policy changes) into Sentinel at no additional cost.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Salesforce audit logs
Why it's wrong here
Salesforce audit logs are not a native Microsoft Sentinel data source; Sentinel has no built-in 'Salesforce' connector in its data connector gallery. Ingesting these logs requires a custom-built solution, such as a Logic App that periodically calls the Salesforce REST API and pushes events into the Log Analytics workspace. Hence, Salesforce audit logs are an incorrect choice for the question of natively supported sources.
- ✗
GitHub audit logs
Why it's wrong here
GitHub audit logs also lack first-class, out-of-the-box support in Microsoft Sentinel. Although Microsoft provides guidance for community solutions, there is no native connector, so you must deploy an Azure Function or Logic App consuming GitHub's Audit Log API and sending the data to Sentinel. This makes GitHub audit logs a custom, non-native integration, unlike the two correct answers.
- ✗
Google Cloud Platform (GCP) logs
Why it's wrong here
Google Cloud Platform (GCP) logs are not natively integrated with Microsoft Sentinel; the platform's native cloud connectors cover AWS CloudTrail, not GCP. To bring GCP logs into Sentinel, organizations typically use third-party collectors or custom ingestion APIs, which means GCP is not one of the two natively supported data sources.
- ✓
Windows Security Events
Why this is correct
Windows Security Events are natively supported through the 'Windows Security Events via AMA' or legacy 'Windows Security Events' connector, which uses the Log Analytics agent (or Azure Monitor Agent) to collect security event logs from Windows machines. This built-in, first-party connector requires no custom development and is a standard source for detecting threats, making it one of the two correct answers.
- ✓
Azure Activity Logs
Why this is correct
Azure Activity Logs are a native data source via the 'Azure Activity' connector in Microsoft Sentinel, which streams subscription-level events such as resource creation, configuration changes, and service health incidents directly from the Azure platform. This first-party connector is installed with a single click and requires no custom code, so Azure Activity Logs correctly qualify as a natively supported data source.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO are supported data sources for Microsoft Sentinel?
easy- A.Google Cloud VPC Flow Logs
- B.Windows Server 2008 event logs
- ✓ C.Microsoft Entra ID audit logs
- ✓ D.AWS CloudTrail
- E.On-premises syslog-ng
Why C: Microsoft Entra ID audit logs (Option C) are a native data source for Microsoft Sentinel because Sentinel is built on Azure Monitor Logs and directly ingests Entra ID (formerly Azure AD) diagnostic settings via the Azure portal or API. This integration requires no additional connectors or agents, as Entra ID audit logs are automatically forwarded to a Log Analytics workspace when configured under 'Diagnostic settings' in the Entra ID blade.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.