SC-100 Windows Security Events via AMA connector Practice Question
You need to design a security operations strategy for a hybrid environment using Microsoft Sentinel. Your environment includes on-premises servers and Azure VMs. Which data connector should you use to collect security events from both sources?
⚠ Common exam trap
Candidates may mistakenly choose the Azure Activity log connector, thinking it covers all Azure resource logs, but it does not capture Windows Security Events from VMs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Security Events via AMA connector
The Windows Security Events via AMA connector is correct because the Azure Monitor Agent (AMA) can be installed on both on-premises Windows servers (via Azure Arc) and Azure VMs, allowing Windows security events to be collected and ingested into Microsoft Sentinel from both sources. This connector uses Data Collection Rules (DCRs) to define which event sets (e.g., All Events, Common, Minimal) are streamed to the Log Analytics workspace. The Azure Activity log connector only captures Azure control-plane/subscription-level operations, not OS security events from servers. The Office 365 connector ingests audit logs from Microsoft 365 services, and the Syslog connector targets Linux/Unix or network appliances via syslog, not Windows security events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Activity log connector
Why it's wrong here
The Azure Activity log connector ingests subscription-level control-plane events, such as virtual machine state changes, resource deployments, and role assignments. It does not capture guest operating system security events like login failures or process creation, which occur after a VM is provisioned. Therefore, it cannot fulfill a hybrid security operations requirement to collect Windows Security Events from Azure VMs or on-premises servers.
- ✓
Windows Security Events via AMA connector
Why this is correct
The Windows Security Events via AMA connector uses the Azure Monitor Agent to collect Windows operating system security events, including common Event IDs such as 4624 (successful logon) and 4625 (failed logon), from both Azure VMs and Arc-enabled on-premises servers. Because it relies on AMA, it provides a single, consistent agent for hybrid environments and supports data collection rules to filter specific security event IDs. This direct, native collection path makes it the correct choice for the scenario.
- ✗
Office 365 connector
Why it's wrong here
The Office 365 connector retrieves audit and operational data from Microsoft 365 services such as Exchange Online, SharePoint, Teams, and Microsoft Entra ID, focusing on user activity, email threats, and app access. It has no visibility into guest operating system security events on Windows endpoints, whether those endpoints are in Azure or on-premises. Therefore, it cannot provide the Windows Security Event data needed for the security operations strategy.
- ✗
Syslog connector
Why it's wrong here
The Syslog connector is built exclusively for Linux servers, network appliances, and firewalls that emit Syslog or Common Event Format (CEF) messages. Windows does not natively send security events via Syslog; it writes them to the Windows Event Log, and without a separate forwarding mechanism or relay, Syslog cannot ingest those events. Thus, it is unsuitable for collecting Windows Security Events in any Windows-centric hybrid environment.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.