Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel for security operations. You need to ensure that a specific AWS CloudTrail log is ingested into Microsoft Sentinel. Which data connector should you use?

⚠ Common exam trap

Many candidates confuse the legacy AWS CloudTrail Connector (Option A) with the modern Amazon Web Services S3 Connector, assuming the name 'CloudTrail' is the correct match, when in fact the S3 connector is the current recommended method for ingesting CloudTrail logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Web Services S3 Connector

The Amazon Web Services S3 Connector is the correct choice because AWS CloudTrail logs are stored as JSON files in an S3 bucket. Microsoft Sentinel ingests these logs by connecting directly to the S3 bucket, reading the CloudTrail log files, and pulling them into the Log Analytics workspace. The AWS CloudTrail Connector, by contrast, is a legacy connector that requires a separate AWS Lambda function and is deprecated in favor of the S3 connector.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail Connector

    Why it's wrong here

    Microsoft Sentinel does not include a dedicated data connector named 'AWS CloudTrail.' CloudTrail logs are delivered to an Amazon S3 bucket, and Sentinel's AWS S3 connector is the mechanism that ingests those logs into the workspace. Attempting to select a separate CloudTrail connector would be impossible in the Sentinel content hub, so this option is incorrect because the CloudTrail logs flow through the S3 connector instead.

  • ✓

    Amazon Web Services S3 Connector

    Why this is correct

    The AWS S3 connector is the correct data connector because it directly ingests CloudTrail log files from an S3 bucket into Microsoft Sentinel. It uses an Azure Functions app to poll the bucket or subscribe to an SQS queue, retrieving CloudTrail JSON objects and translating them into the AWSCloudTrail table. This makes it the sole standard first-party connector for shipping CloudTrail logs into the SIEM.

  • ✗

    Azure Functions (AWS)

    Why it's wrong here

    Azure Functions is not a data connector; it is the serverless compute runtime that the AWS S3 connector uses in a Log Analytics workspace. While 'Azure Functions (AWS)' sounds technical, the actual connector name in Sentinel is simply 'Amazon Web Services S3' or 'CloudTrail' via S3. Without the S3 connector wrapper, an Azure Functions app alone cannot ingest any AWS logs, making this option semantically wrong.

  • ✗

    AWS Security Hub Connector

    Why it's wrong here

    The AWS Security Hub connector ingests aggregated security findings (such as GuardDuty findings and compliance checks) into the AWSRecommendation and ASim* tables, not raw CloudTrail event logs. CloudTrail records are granular API activity logs, which are a different data type that Security Hub does not forward. Therefore, this connector cannot satisfy the requirement to ingest CloudTrail logs, so it is incorrect.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.