Courseiva

Detecting Data Exfiltration from Azure SQL Database Using Microsoft Sentinel

A company uses Microsoft Sentinel for security operations. They want to collect logs from a custom application running on Azure Virtual Machines. The application writes logs to a local file. Which data connector should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Custom Logs via Log Analytics agent

The correct option is D, Custom Logs via Log Analytics agent, because Microsoft Sentinel can ingest arbitrary text-based log files from Azure VMs by installing the Log Analytics agent (MMA/AMA) and defining a custom log table that points to the local file path, which is exactly the scenario of a custom application writing to a local file. Application Insights (A) is an APM service for instrumented application telemetry, not for collecting pre-existing local log files from VMs. Syslog (B) only handles syslog-format messages from Linux/network devices, and Windows Event Forwarding (C) only collects Windows Event Log data, so neither fits a custom application's local log file.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Application Insights

    Why it's wrong here

    Application Insights is Azure Monitor's application performance management (APM) service, designed to receive telemetry streamed from instrumented application code via SDKs (e.g., requests, dependencies, exceptions). It does not perform file system scanning or monitor arbitrary directories for pre-existing log files; it simply has no mechanism to ingest flat .log or .txt files generated by custom applications unless that code explicitly sends telemetry to an Application Insights resource. Therefore, it cannot satisfy a requirement to collect existing custom application log files from a VM.

  • ✗

    Syslog

    Why it's wrong here

    Syslog is a network logging protocol used primarily by Linux/Unix hosts, network appliances, and firewalls to send structured event messages over UDP/TCP (typically port 514) to a central collector. The Microsoft Sentinel Syslog connector relies on the Log Analytics agent to receive and parse those RFC 3164/5424 syslog messages — not to read arbitrary text-based application log files with custom formatting. Even though some applications can be configured to write to syslog, the question expects ingesting existing log files directly from disk, which Syslog does not do unless the application is modified to emit syslog messages.

  • ✗

    Windows Event Forwarding

    Why it's wrong here

    Windows Event Forwarding (WEF) uses the Windows Remote Management (WinRM) protocol to forward Windows Event Log entries from source computers to an event collector, then those events can be ingested into Microsoft Sentinel via the Windows Event Log connector. WEF works exclusively with the structured Event Log service (Security, System, Application channels); it has no capability to read or forward plain-text log files created by custom applications outside of the Windows Event Log subsystem. Therefore, it is unsuitable for ingesting a custom application's file-based logs.

  • ✓

    Custom Logs via Log Analytics agent

    Why this is correct

    Custom Logs via the Log Analytics agent is the correct solution because the agent provides a native 'Custom Logs' feature that lets you specify a local directory and file mask (e.g., C:\Logs\*.log or /var/log/app/*.txt) to continuously monitor. When a new entry is appended to a matching file, the agent reads it, parses each line using a sample-based custom log definition, and sends the data to a custom table (e.g., MyLog_CL) in the Log Analytics workspace, which Microsoft Sentinel can then query and alert on. This is the built-in method specifically designed to collect existing application-generated log files from Windows or Linux VMs without requiring code changes.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your company uses Microsoft Sentinel for security operations. You need to design a solution that automatically remediates a detected threat by blocking a malicious IP address on Azure Firewall. Which Microsoft Sentinel feature should you use?

medium
  • A.Analytics rules
  • B.Workbooks
  • ✓ C.SOAR playbooks
  • D.User and Entity Behavior Analytics (UEBA)

Why C: Security Orchestration, Automation, and Response (SOAR) in Microsoft Sentinel uses playbooks to automate remediation actions like blocking IPs on Azure Firewall. Option A is wrong because analytics rules only generate alerts. Option B is wrong because workbooks visualize data. Option D is wrong because UEBA analyzes behavior but does not automate remediation.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.