SC-100 Design security solutions for infrastructure Practice Question
Your company uses Microsoft Sentinel for security operations. You need to detect brute-force attacks against Azure VMs by correlating failed sign-in events from multiple sources. Which data connector should you enable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Security Events via AMA (Azure Monitor Agent) connector.
The Windows Security Events via AMA connector is correct because it collects Windows security event logs—including failed logon events (Event ID 4625)—from Azure VMs into Microsoft Sentinel, enabling correlation of brute-force attempts across multiple sources. The Microsoft Entra ID (Microsoft Entra ID) sign-in logs connector only ingests Entra ID authentication events, not local or VM-level Windows logon failures. The Syslog connector targets Linux/network device logs (e.g., via rsyslog) and does not capture Windows Security event data. The Azure Activity log connector records Azure control-plane operations (resource changes), not sign-in or authentication events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID (now Microsoft Entra ID) sign-in logs connector.
Why it's wrong here
The Microsoft Entra ID (formerly Azure AD) sign-in logs connector records interactive and non-interactive authentication against Microsoft Entra ID, such as users signing in to Office 365 or to Entra ID-backed applications. However, sign-ins directly to an Azure Windows VM (via RDP or SSH) are local operating system logons validated against the VM's SAM or domain membership, not against Entra ID, unless the VM is Entra ID-joined and using specific extensions. Even in hybrid scenarios, the raw failed logon event (4625) is generated in the VM's Security log and requires the Windows Security Events connector to be ingested into Sentinel.
- ✗
Syslog connector.
Why it's wrong here
The Syslog connector is designed to collect CEF-formatted syslog messages from on-premises or Linux-based security appliances and Unix-like hosts, not from Windows VMs. Windows Server does not natively emit failed sign-in events as syslog messages, so Event ID 4625 would never appear in a syslog stream. Furthermore, even if the VM were Linux, Syslog does not parse the Windows Security log; the connector would require a syslog daemon and a separate integration, making it an indirect and inappropriate choice for this requirement.
- ✓
Windows Security Events via AMA (Azure Monitor Agent) connector.
Why this is correct
The Windows Security Events via AMA connector is purpose-built to stream Windows Security log entries, including Event ID 4625 (failed sign-in), from Azure VMs and other Windows machines. It uses Azure Monitor Agent (AMA) to collect specified security event IDs and send them to Sentinel, enabling near-real-time detection and investigation of brute-force or credential-stuffing attempts. This connector also supports filtering by event ID, so you can efficiently ingest only 4625 and other high-value security events without overwhelming log storage.
- ✗
Azure Activity log connector.
Why it's wrong here
The Azure Activity log connector captures control-plane (management) events such as VM creation, deletion, and configuration changes, which are recorded at the Azure Resource Manager level. VM user sign-in events, including failed sign-in attempts, occur within the guest operating system and are written to the local Windows Security log (Event ID 4625). Therefore, this connector would neither collect the required event nor detect unauthorized access to the VM's desktop or RDP session.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.