SC-100 Practice Question: Design solutions that align with security best practices and priorities
A company is designing a security operations center (SOC). They want to use Microsoft Sentinel as their SIEM. They need to ensure that all security events from on-premises servers are collected. Which data connector should they configure?
⚠ Common exam trap
A common mix-up: candidates confuse Syslog (used for Linux/network devices) with Windows Security Events, or mistakenly think the legacy Log Analytics Agent (now deprecated) is still the primary connector for Windows events, when AMA is the current best practice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Security Events via Azure Monitor Agent (AMA)
The Windows Security Events via Azure Monitor Agent (AMA) connector is the recommended method for collecting security events from on-premises Windows servers into Microsoft Sentinel. AMA is the current generation agent that supports data collection rules (DCRs) for granular filtering and is fully supported by Sentinel, replacing the legacy Log Analytics Agent. This ensures comprehensive collection of Windows security logs such as Event ID 4625 (failed logons) and 4688 (process creation) for SOC analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Windows Firewall via Legacy Agent
Why it's wrong here
Windows Firewall via Legacy Agent is incorrect because the Legacy Agent (Microsoft Monitoring Agent) is deprecated and should not be used for new SOC telemetry pipelines; it has been replaced by Azure Monitor Agent. Additionally, Windows Firewall itself is a host-based packet filter that does not generate detailed security audit events such as logon activity or process creation—it only logs connection attempts. Without the agent reading Security event logs, the SOC would miss the required visibility into on-premises Windows servers.
- ✗
Syslog via AMA
Why it's wrong here
Syslog via AMA is not the right choice because Syslog is primarily a logging protocol used by Linux hosts, network appliances, and other non-Windows devices. While Azure Monitor Agent can collect Syslog messages, Windows servers natively write security events to the Windows Event Log channels (e.g., Security, System, Application) rather than to Syslog. Unless you install additional forwarding software, Windows Security events will not appear as Syslog, so this option would not deliver the required on-premises Windows security telemetry.
- ✗
Azure Activity Log
Why it's wrong here
Azure Activity Log is incorrect because it provides diagnostic information about the Azure resource management plane—such as creating, updating, or deleting Azure resources—not the OS-level security events generated by on-premises Windows servers. Even for Azure VMs, Activity Log does not capture guest OS security events such as event IDs 4624/4625 (logon success/failure) or 4688 (process creation). Since the scenario explicitly involves on-premises servers, this cloud-only log cannot fulfill the SOC's data collection requirement.
- ✓
Windows Security Events via Azure Monitor Agent (AMA)
Why this is correct
Windows Security Events via Azure Monitor Agent (AMA) is the correct approach because AMA supports collection of Windows Security event logs from on-premises servers when they are connected via Azure Arc. The agent can be configured with Data Collection Rules (DCRs) to filter specific event IDs (e.g., 4624, 4688) and forward them to a Log Analytics workspace for analysis in Microsoft Sentinel or Microsoft Defender for Endpoint. This modern method replaces the deprecated Legacy Agent and provides the granular security telemetry needed by the SOC.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.