SC-200 Manage a security operations environment Practice Question
You are configuring Microsoft Sentinel to ingest data from multiple sources. Which TWO of the following are valid data connectors that can be used to ingest AWS CloudTrail logs?
⚠ Common exam trap
Many exam-takers assume only the AWS S3 connector is valid, forgetting that Azure Functions can also serve as a custom data connector for AWS CloudTrail logs when configured with the appropriate trigger and permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Functions connector
The AWS S3 connector (Option C) is a valid data connector for ingesting AWS CloudTrail logs into Microsoft Sentinel by reading the logs directly from an S3 bucket. The Azure Functions connector (Option A) is also valid because it can be configured to trigger on CloudTrail log delivery to S3, using a function app to parse and forward the logs to Sentinel via the Log Analytics HTTP Data Collector API.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Functions connector
Why this is correct
Azure Functions can be deployed to create a custom ingestion pipeline for AWS CloudTrail logs. This involves configuring an Azure Function to retrieve logs from the designated AWS S3 bucket where CloudTrail stores its data. The function then processes these logs and forwards them to the Microsoft Sentinel Log Analytics workspace, effectively satisfying the requirement to ingest AWS CloudTrail logs. This method offers flexibility for custom transformations or filtering before ingestion.
- ✗
Office 365 connector
Why it's wrong here
The Office 365 connector is purpose-built to collect audit and activity logs from Microsoft 365 services such as Exchange Online, SharePoint Online, and Teams via the Office 365 Management Activity API. It has no integration with AWS APIs or S3 storage, so it cannot retrieve CloudTrail events from AWS. Because its data source is entirely inside Microsoft's cloud, this connector would not meet a requirement to ingest AWS CloudTrail logs, even if the organization also uses Microsoft 365.
- ✓
AWS S3 connector
Why this is correct
The AWS S3 connector is the native, first-party connector in Microsoft Sentinel for ingesting AWS CloudTrail data. It works by assuming an IAM role to read CloudTrail JSON log files directly from a designated S3 bucket, supporting management, data, and insight events across multiple AWS accounts. This is the most direct and documented method for CloudTrail ingestion, requiring minimal custom code, and properly satisfies the requirement to ingest AWS CloudTrail logs.
- ✗
Microsoft Defender for Cloud connector
Why it's wrong here
The Microsoft Defender for Cloud connector is designed to pull security alerts and posture recommendations from Defender for Cloud into Sentinel, focusing on Azure subscriptions and hybrid workloads protected by Defender. It does not include any AWS S3 or CloudTrail integration; its data sources are Azure-native or reliant on Defender's own agents and connectors. Consequently, it cannot ingest AWS CloudTrail logs from S3 buckets, so it is not a valid choice for this scenario.
- ✗
Syslog connector
Why it's wrong here
The Syslog connector receives event messages over the syslog protocol (UDP/TCP) from network appliances, Linux servers, and other syslog-compatible devices. AWS CloudTrail logs are not emitted via syslog; they are delivered as JSON-formatted object files on S3, which is a completely different transport and storage mechanism. Even if an intermediary syslog forwarder were placed in front of AWS, CloudTrail has no native syslog output capability, so this connector cannot satisfy the ingestion requirement.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.