Courseiva

SC-200 Manage a security operations environment Practice Question

You are configuring Microsoft Sentinel to ingest data from multiple sources. Which TWO of the following are valid data connectors that can be used to ingest AWS CloudTrail logs?

⚠ Common exam trap

Many exam-takers assume only the AWS S3 connector is valid, forgetting that Azure Functions can also serve as a custom data connector for AWS CloudTrail logs when configured with the appropriate trigger and permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Functions connector

The AWS S3 connector (Option C) is a valid data connector for ingesting AWS CloudTrail logs into Microsoft Sentinel by reading the logs directly from an S3 bucket. The Azure Functions connector (Option A) is also valid because it can be configured to trigger on CloudTrail log delivery to S3, using a function app to parse and forward the logs to Sentinel via the Log Analytics HTTP Data Collector API.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Functions connector

    Why this is correct

    Azure Functions can be deployed to create a custom ingestion pipeline for AWS CloudTrail logs. This involves configuring an Azure Function to retrieve logs from the designated AWS S3 bucket where CloudTrail stores its data. The function then processes these logs and forwards them to the Microsoft Sentinel Log Analytics workspace, effectively satisfying the requirement to ingest AWS CloudTrail logs. This method offers flexibility for custom transformations or filtering before ingestion.

  • ✗

    Office 365 connector

    Why it's wrong here

    The Office 365 connector is purpose-built to collect audit and activity logs from Microsoft 365 services such as Exchange Online, SharePoint Online, and Teams via the Office 365 Management Activity API. It has no integration with AWS APIs or S3 storage, so it cannot retrieve CloudTrail events from AWS. Because its data source is entirely inside Microsoft's cloud, this connector would not meet a requirement to ingest AWS CloudTrail logs, even if the organization also uses Microsoft 365.

  • ✓

    AWS S3 connector

    Why this is correct

    The AWS S3 connector is the native, first-party connector in Microsoft Sentinel for ingesting AWS CloudTrail data. It works by assuming an IAM role to read CloudTrail JSON log files directly from a designated S3 bucket, supporting management, data, and insight events across multiple AWS accounts. This is the most direct and documented method for CloudTrail ingestion, requiring minimal custom code, and properly satisfies the requirement to ingest AWS CloudTrail logs.

  • ✗

    Microsoft Defender for Cloud connector

    Why it's wrong here

    The Microsoft Defender for Cloud connector is designed to pull security alerts and posture recommendations from Defender for Cloud into Sentinel, focusing on Azure subscriptions and hybrid workloads protected by Defender. It does not include any AWS S3 or CloudTrail integration; its data sources are Azure-native or reliant on Defender's own agents and connectors. Consequently, it cannot ingest AWS CloudTrail logs from S3 buckets, so it is not a valid choice for this scenario.

  • ✗

    Syslog connector

    Why it's wrong here

    The Syslog connector receives event messages over the syslog protocol (UDP/TCP) from network appliances, Linux servers, and other syslog-compatible devices. AWS CloudTrail logs are not emitted via syslog; they are delivered as JSON-formatted object files on S3, which is a completely different transport and storage mechanism. Even if an intermediary syslog forwarder were placed in front of AWS, CloudTrail has no native syslog output capability, so this connector cannot satisfy the ingestion requirement.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.