AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
A company is deploying Microsoft Sentinel in a new Azure subscription. The security team wants to ingest Windows security events from on-premises servers. Which data connector should they use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Security Events via AMA (Azure Monitor Agent)
The Windows Security Events via AMA connector is the current recommended method for streaming Windows security events to Azure Sentinel using the Azure Monitor Agent. Option B is wrong because the Microsoft Entra ID connector is for Microsoft Entra ID logs, not Windows events. Option C is wrong because the Office 365 connector is for Office logs. Option D is wrong because the Common Event Format (CEF) connector is for syslog from security appliances, not Windows security events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Windows Security Events via AMA (Azure Monitor Agent)
Why this is correct
The Windows Security Events via AMA connector is the correct choice because Azure Monitor Agent (AMA) is the modern agent that collects Windows Event Logs, including the Security channel, using a Data Collection Rule (DCR). This connector streams events such as successful/failed logons, process creation, and privilege use directly into Sentinel's WindowsEvent table, making it the current standard for this source. Unlike the legacy Log Analytics agent, AMA provides a single agent for both Log Analytics and extension-based workloads, with more granular filtering and network-friendly control.
- ✗
Office 365 connector
Why it's wrong here
The Office 365 connector ingests Microsoft 365 audit logs — covering Exchange, SharePoint, OneDrive, and Teams activities — but it does not read local Windows event logs from domain-joined or standalone servers. Its purpose is cloud application activity, not OS-level security events such as logon attempts or process execution on a Windows machine. Therefore, while it is a valid Sentinel data source, it cannot satisfy this requirement.
- ✗
Microsoft Entra ID connector
Why it's wrong here
The Microsoft Entra ID (now Microsoft Entra ID) connector ingests identity-related audit data, including sign-in logs, audit logs, and provisioning events, which track user and service principal activity in the directory. These are not Windows security events from the local Security log, so they lack OS-level telemetry like kernel mode audit events or local account logons. It is incorrect here because the requirement specifically asks for Windows security events, not cloud identity events.
- ✗
Common Event Format (CEF) connector
Why it's wrong here
The Common Event Format (CEF) connector is designed for external security devices — such as firewalls, proxies, and network intrusion detection systems — that forward logs over syslog in CEF format, typically to a log forwarder VM. It does not collect Windows Event Logs directly; Windows security events are natively generated in Event Tracing for Windows (ETW) and Windows Event Log channels, not syslog/CEF. Thus, using CEF would require a third-party agent that translates Windows events into CEF, which is a misaligned and inefficient approach for this scenario.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.