Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Manage identity and access Practice Question

A security operations team uses Microsoft Sentinel. They need to collect Syslog messages from on-premises Linux servers for analysis. Which data connector should they use to ingest these logs into Sentinel?

⚠ Common exam trap

Many candidates confuse the Syslog connector (for standard Syslog) with the CEF connector (for formatted security logs), mistakenly thinking CEF is required for any Linux Syslog ingestion, when in fact CEF is only needed for specific security appliances that output CEF-formatted logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Syslog connector via Log Analytics agent

The Syslog connector via Log Analytics agent is the correct choice because it allows Microsoft Sentinel to collect Syslog messages from on-premises Linux servers. The Log Analytics agent (formerly OMS agent) listens on UDP port 514 (or a custom port) for Syslog messages forwarded by the Linux rsyslog or syslog-ng daemon, then forwards them to the Log Analytics workspace. This connector is specifically designed for standard Syslog ingestion without requiring format transformation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Activity Log connector

    Why it's wrong here

    The Azure Activity Log connector is exclusively designed to ingest subscription-level operational events such as resource creation, RBAC changes, and service health alerts. It relies on Azure Monitor diagnostic settings and exports to a Log Analytics workspace, but it has no mechanism to receive raw Syslog traffic from Linux hosts or network devices. Therefore, it cannot fulfill the requirement for collecting on-premises Syslog data.

  • ✓

    Syslog connector via Log Analytics agent

    Why this is correct

    The Syslog connector via the Log Analytics agent is the correct choice for ingesting standard Syslog messages into Microsoft Sentinel. To use it, you must install the Log Analytics agent on a Linux virtual machine (on-premises or in Azure) that acts as a Syslog collector, then configure the agent's syslog daemon to forward events with specific facilities and severities. The connector then maps those events to the Syslog table in the workspace, enabling detection rules and queries.

  • ✗

    Common Event Format (CEF) connector

    Why it's wrong here

    The Common Event Format (CEF) connector is tailored for security appliances that emit logs in the ArcSight CEF format—a structured key-value syntax that includes a specific header. While CEF can be transported over Syslog, this connector expects a particular message format and often requires a separate CEF-forwarding agent or a Linux VM configured to parse CEF, not raw Syslog. General Syslog messages lacking CEF headers will be dropped or misparsed, making it unsuitable for this scenario.

  • ✗

    Windows Security Events connector

    Why it's wrong here

    The Windows Security Events connector is built to collect security-relevant event logs from Windows machines, such as logon events, process creation, and audit failures. It uses the Windows Log Analytics agent or Azure Monitor Agent to read the Windows Event Log, and it has no capability to ingest Linux Syslog messages. Since the requirement explicitly involves Syslog, which is native to Linux networking and other devices, this connector cannot provide the needed data.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.