SC-100 Design security solutions for infrastructure Practice Question
An organization uses Microsoft Sentinel to monitor their hybrid infrastructure. They need to detect brute-force attacks against their on-premises Windows servers. Which data source should they connect to Sentinel?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Security Events via Azure Monitor Agent
Windows Security Events from Event ID 4625 (failed logon) are the primary source for detecting brute-force attacks. Azure Activity Log is for resource management events. DNS events are for DNS queries. Sysmon is for process activity, not logon failures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Activity Log
Why it's wrong here
Azure Activity Log records subscription-level control plane operations such as resource creation, deletion, and configuration changes, not security authentication events. Failed logon attempts to hybrid workloads occur at the operating system or domain controller level and do not generate entries in the Activity Log. Since it lacks Event 4625 or any logon event, it cannot be used to detect brute-force attacks or credential stuffing.
- ✓
Windows Security Events via Azure Monitor Agent
Why this is correct
The Windows Security event log via the Azure Monitor Agent (AMA) is the standard and authoritative source for logon audit events, specifically Event ID 4625, which logs every failed account logon attempt. For hybrid machines, configuring a data collection rule (DCR) to forward Security events to Microsoft Sentinel enables detection of password-spraying and brute-force attempts. AMA is the current agent replacing the Log Analytics agent and preserves the necessary event details, such as source IP and target account, for high-fidelity analytics.
- ✗
DNS Events
Why it's wrong here
DNS events capture domain name resolution queries and responses, which are valuable for detecting command-and-control (C2) traffic or domain generation algorithms, but they are unrelated to user authentication failures. A failed logon attempt on a hybrid server does not generate a DNS query or DNS log entry; the failure occurs in the authentication protocol (like Kerberos or NTLM) and is recorded in the security log. Thus, using DNS events as a data source would miss all logon failures and cannot address a brute-force detection scenario.
- ✗
Sysmon Events
Why it's wrong here
Sysmon, unless explicitly configured with a custom configuration to audit logon events, primarily logs process creation (Event ID 1), network connections (Event ID 3), and file/image loads. While Sysmon can log successful logons (Event ID 4624) with certain configurations, failed logons (Event ID 4625) are not among its default or typical event types. Relying solely on Sysmon events would therefore miss failed logon attempts, whereas the Windows Security log inherently captures 4625 events by default when auditing is enabled.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.