Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel with the Azure Activity connector. Which TWO actions should you take to ensure that all subscription-level activity logs are being ingested into Sentinel?

⚠ Common exam trap

Many candidates confuse the Azure Activity connector's requirement for a managed identity role assignment with the diagnostic settings method used by other data connectors, leading them to incorrectly select option B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign the 'Reader' role to the Sentinel managed identity on each subscription.

The Azure Activity data connector uses a managed identity to read subscription-level activity logs. Assigning the 'Reader' role to that managed identity on each subscription grants it the necessary permissions to access and ingest the logs into Sentinel. Without this role assignment, the connector cannot retrieve the activity data, even if the connector is configured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Install the Azure Activity solution from the content hub.

    Why it's wrong here

    The Azure Activity solution from the content hub is an optional bundle of workbooks, analytics rules, and playbooks that help you visualize and respond to activity log data. It does not by itself configure the underlying data connector or grant any permissions, and basic ingestion of activity logs works without installing it. The solution should be installed only after the connector is successfully collecting data and you want enrichments or monitoring content.

  • ✗

    Enable diagnostic settings on each subscription to stream logs to the Sentinel Log Analytics workspace.

    Why it's wrong here

    Diagnostic settings are typically used to stream resource-level logs from Azure services to a Log Analytics workspace, but they are not the mechanism the Azure Activity data connector uses for subscription-level activity logs. Even though you can create a diagnostic setting for the Activity log, that is an alternative export path that bypasses the connector and would not satisfy the connector's configuration requirement. The connector instead directly ingests Activity log records after you select subscriptions and assign the Sentinel managed identity the Reader role.

  • ✓

    Assign the 'Reader' role to the Sentinel managed identity on each subscription.

    Why this is correct

    The Sentinel workspace's managed identity must be assigned the Reader role on each subscription that will contribute activity logs. This role allows the Azure Activity data connector to call the Azure Monitor Activity Log API and retrieve subscription-level audit events. Without this permission grant, the connector will show success but collect zero records, or will fail authentication when polling for new activity.

  • ✓

    Configure the Azure Activity data connector to include all subscriptions.

    Why this is correct

    In the connector's configuration blade, you must explicitly select all the subscriptions whose activity logs you want to ingest. Only after you enable the subscription checkboxes and apply the configuration does the connector begin collecting activity from those subscriptions. This subscription selection is a separate step from role assignment; you can have the Reader role on a subscription but if it's not selected in the connector, no data is ingested. The connector's UI shows the list of subscriptions accessible by the managed identity, and you must verify every intended subscription is selected.

  • ✗

    Use the Azure Policy initiative to deploy the connector.

    Why it's wrong here

    Azure Policy is used to audit or remediate configuration drift across resources in a subscription, not to enable a Sentinel data connector's runtime authentication or subscription selection. While a policy initiative could theoretically assign a role at scale, the Azure Activity connector's subscription list is managed within the Sentinel workspace UI and cannot be configured via a built-in policy. Deploying the connector is a one-time manual or template-based operation, and policy is not a required or standard part of that process.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.