Courseiva

Gathering Context About a User Entity in Microsoft Sentinel

A security analyst is using Microsoft Sentinel to investigate an incident. Which THREE data sources can be ingested into Sentinel?

⚠ Common exam trap

It's easy for candidates to assume any Microsoft service log can be ingested into Sentinel, but only services with dedicated, built-in data connectors (like Microsoft Entra ID, Office 365, and Windows Security Events) are directly supported, while others like Power BI and Azure DevOps require custom or third-party solutions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID logs

Microsoft Sentinel natively supports ingesting Microsoft Entra ID (Azure AD) sign-in and audit logs through the Microsoft Entra ID data connector, making option B correct for identity-based threat detection. Option C is correct because Office 365 logs (Exchange, SharePoint, Teams, etc.) are ingested via the Office 365 connector using the Office 365 Management Activity API. Option D is correct because Windows Security Events can be collected via the Azure Monitor Agent (AMA) or the Log Analytics agent using the Windows Security Events via AMA connector or the Security Events connector. Option A is not a supported Sentinel data source, as Power BI usage metrics are not part of Sentinel's built-in connectors. Option E is also not a standard Sentinel connector; Azure DevOps audit logs are not natively ingested into Sentinel without custom workarounds.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Power BI usage metrics

    Why it's wrong here

    Power BI usage metrics, while valuable for understanding adoption and performance, are not directly ingested into Microsoft Sentinel as a native data connector for security analysis. Sentinel primarily focuses on security-relevant logs and events from services like Microsoft Entra ID, Office 365, and various infrastructure components. While custom ingestion via Azure Data Factory or Logic Apps is theoretically possible, it's not a standard or recommended method for these specific metrics, making it an unsupported direct data source.

  • ✓

    Microsoft Entra ID logs

    Why this is correct

    Microsoft Sentinel offers a robust, out-of-the-box data connector for Microsoft Entra ID, enabling the ingestion of critical identity-related logs such as sign-in logs, audit logs, and provisioning logs. These logs are fundamental for detecting suspicious authentication attempts, privilege escalation, and other identity-based threats across an organization's cloud identity infrastructure. The connector streams these events directly into a Log Analytics workspace for real-time analysis and correlation with other security data.

  • ✓

    Office 365 logs

    Why this is correct

    Microsoft Sentinel provides a dedicated connector to ingest audit logs from various Office 365 services, including Exchange Online, SharePoint Online, and Microsoft Teams. This allows security analysts to monitor user and administrative activities within productivity applications, identifying potential data exfiltration, unauthorized access, or policy violations. The Office 365 connector is crucial for comprehensive cloud application security monitoring and compliance.

  • ✓

    Windows Security Events

    Why this is correct

    Windows Security Events are a cornerstone of endpoint security monitoring and are fully supported for ingestion into Microsoft Sentinel. These events, encompassing logon/logoff activities, process creation, and object access, are collected from Windows servers and workstations using either the legacy Microsoft Monitoring Agent (MMA) or the modern Azure Monitor Agent (AMA). The agents forward these critical security logs to a Log Analytics workspace for centralized analysis, threat detection, and incident response.

  • ✗

    Azure DevOps audit logs

    Why it's wrong here

    While Azure DevOps generates audit logs that are crucial for monitoring development pipeline security, Microsoft Sentinel does not currently offer a direct, out-of-the-box data connector specifically for Azure DevOps audit logs. Ingesting these logs would typically require a custom solution, such as exporting them to Azure Storage and then using Azure Logic Apps or Azure Functions to push them into a Log Analytics workspace. This makes it a non-standard, more complex ingestion scenario compared to native connectors.

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.