SC-200 Manage a security operations environment Practice Question
Your organization is implementing Microsoft Sentinel. You need to ensure that security events from AWS CloudTrail are collected. What should you configure?
⚠ Common exam trap
Many exam-takers confuse Microsoft Defender for Cloud's AWS monitoring capabilities (which focus on security posture and alerts) with the log ingestion needed for Sentinel, leading them to choose Option C instead of the dedicated S3 connector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS S3 connector in Sentinel.
The AWS S3 connector in Microsoft Sentinel is the correct solution because AWS CloudTrail logs are stored in an S3 bucket. Sentinel's native AWS S3 connector ingests these logs by polling the S3 bucket for new CloudTrail events, parsing them into the Sentinel workspace for security monitoring. This is the designated method for collecting CloudTrail data into Sentinel, as documented by Microsoft.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Policy to audit AWS resources.
Why it's wrong here
Azure Policy is an Azure-native governance service designed to audit, enforce, and remediate compliance rules on Azure resources. It has no data-plane mechanism to pull logs from external SaaS platforms like AWS, and it cannot capture CloudTrail records into Microsoft Sentinel. Even with Azure Arc or custom policies, it remains a resource compliance tool, not a SIEM data connector. Therefore it is entirely incapable of satisfying the requirement to ingest AWS CloudTrail logs.
- ✓
AWS S3 connector in Sentinel.
Why this is correct
The AWS S3 connector in Microsoft Sentinel is the native, documented data connector specifically built to ingest AWS CloudTrail logs. It works by configuring an Amazon S3 bucket to receive CloudTrail logs, with Simple Queue Service (SQS) providing real-time notifications that Sentinel's connector consumes to pull log data. This connector automatically maps CloudTrail records to the AWSCloudTrail table, enabling standard KQL queries, analytics rules, and incident handling. Because it is purpose-built for this exact use case, it is the correct and recommended solution.
- ✗
Microsoft Defender for Cloud to monitor AWS.
Why it's wrong here
Microsoft Defender for Cloud does have an AWS connector that enables multi-cloud security posture management, bringing AWS resource visibility, security recommendations, and threat detection alerts into Defender for Cloud. However, that connector does not directly ingest raw CloudTrail logs into Sentinel; instead, it forwards high-level security alerts and findings, which are a filtered, aggregated subset of data. To feed raw AWS audit logs into Sentinel for full SIEM analysis, a separate data connector such as the AWS S3 connector is required. Thus, Defender for Cloud is insufficient for this specific requirement.
- ✗
A REST API connector to call CloudTrail API.
Why it's wrong here
While it is technically possible to write a custom script or logic app that calls the AWS CloudTrail API to retrieve events, Microsoft Sentinel does not provide a built-in REST API data connector for CloudTrail. Building such a custom solution would require creating a scheduled job, handling API pagination, retries, authentication, and log normalization—all of which adds Unnecessary complexity and maintenance overhead. The AWS S3 connector already provides a streamlined, fully supported integration for the exact same log source. Therefore, a custom REST API connector is not only redundant but also a less reliable and unsupported approach compared to the native S3 connector.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.