Courseiva

SC-100 Windows Security Events via AMA connector Practice Question

You need to design a security operations strategy for a hybrid environment using Microsoft Sentinel. Your environment includes on-premises servers and Azure VMs. Which data connector should you use to collect security events from both sources?

⚠ Common exam trap

Candidates may mistakenly choose the Azure Activity log connector, thinking it covers all Azure resource logs, but it does not capture Windows Security Events from VMs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows Security Events via AMA connector

The Windows Security Events via AMA connector is correct because the Azure Monitor Agent (AMA) can be installed on both on-premises Windows servers (via Azure Arc) and Azure VMs, allowing Windows security events to be collected and ingested into Microsoft Sentinel from both sources. This connector uses Data Collection Rules (DCRs) to define which event sets (e.g., All Events, Common, Minimal) are streamed to the Log Analytics workspace. The Azure Activity log connector only captures Azure control-plane/subscription-level operations, not OS security events from servers. The Office 365 connector ingests audit logs from Microsoft 365 services, and the Syslog connector targets Linux/Unix or network appliances via syslog, not Windows security events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Activity log connector

    Why it's wrong here

    The Azure Activity log connector ingests subscription-level control-plane events, such as virtual machine state changes, resource deployments, and role assignments. It does not capture guest operating system security events like login failures or process creation, which occur after a VM is provisioned. Therefore, it cannot fulfill a hybrid security operations requirement to collect Windows Security Events from Azure VMs or on-premises servers.

  • ✓

    Windows Security Events via AMA connector

    Why this is correct

    The Windows Security Events via AMA connector uses the Azure Monitor Agent to collect Windows operating system security events, including common Event IDs such as 4624 (successful logon) and 4625 (failed logon), from both Azure VMs and Arc-enabled on-premises servers. Because it relies on AMA, it provides a single, consistent agent for hybrid environments and supports data collection rules to filter specific security event IDs. This direct, native collection path makes it the correct choice for the scenario.

  • ✗

    Office 365 connector

    Why it's wrong here

    The Office 365 connector retrieves audit and operational data from Microsoft 365 services such as Exchange Online, SharePoint, Teams, and Microsoft Entra ID, focusing on user activity, email threats, and app access. It has no visibility into guest operating system security events on Windows endpoints, whether those endpoints are in Azure or on-premises. Therefore, it cannot provide the Windows Security Event data needed for the security operations strategy.

  • ✗

    Syslog connector

    Why it's wrong here

    The Syslog connector is built exclusively for Linux servers, network appliances, and firewalls that emit Syslog or Common Event Format (CEF) messages. Windows does not natively send security events via Syslog; it writes them to the Windows Event Log, and without a separate forwarding mechanism or relay, Syslog cannot ingest those events. Thus, it is unsuitable for collecting Windows Security Events in any Windows-centric hybrid environment.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.