SC-100 Practice Question: Design security solutions for applications and data
Your organization is planning to use Microsoft Sentinel for security information and event management (SIEM). You need to ingest security logs from on-premises Active Directory. What should you deploy?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Monitor Agent
The correct option is D, Azure Monitor Agent (AMA). AMA is the current, supported agent for collecting data into Log Analytics workspaces, which back Microsoft Sentinel, and it supports Data Collection Rules (DCRs) to ingest Windows security events from on-premises Active Directory domain controllers via the Azure Arc-enabled servers or the AMA extension. The Microsoft Monitoring Agent (A) and the Log Analytics agent (B) are legacy agents that are deprecated for Sentinel data collection and are being replaced by AMA. The Microsoft Defender for Cloud agent (C) is not a standalone log-ingestion agent for Sentinel; Defender for Cloud uses the Log Analytics/AMA agents for data collection, so it does not fit the requirement directly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Monitoring Agent (MMA)
Why it's wrong here
Microsoft Monitoring Agent (MMA) is the legacy agent that has been deprecated in favor of the Azure Monitor Agent. It was originally designed for on-premises and Azure VMs, but its architecture relies on the Log Analytics workspace gateways and custom performance counters that are now outdated. New Sentinel deployments should not use MMA because it will be retired and lacks the modern data collection rules and multi-homing capabilities of AMA.
- ✗
Log Analytics agent
Why it's wrong here
The Log Analytics agent is effectively the same legacy agent as MMA, just under a different name when deployed for Log Analytics workspaces. It is not a separate or modern solution for Sentinel; it shares the same retirement timeline and limitations as MMA. Unlike Azure Monitor Agent, it cannot use data collection rules for granular, per-data source filtering, nor does it support advanced features like Windows Event forwarding or Azure Arc over a single unified pipeline.
- ✗
Microsoft Defender for Cloud agent
Why it's wrong here
Microsoft Defender for Cloud agent is purpose-built to collect security-related telemetry for Defender for Cloud's posture and threat detection, not to ingest all Windows event logs and custom logs needed by Sentinel. While it may forward some security events, it does not provide the comprehensive data collection of the Azure Monitor Agent, which can gather Windows Event logs, Syslog, custom JSON, and performance counters under flexible data collection rules. Relying on this agent would leave Sentinel starved of the broad telemetry it needs for full visibility.
- ✓
Azure Monitor Agent
Why this is correct
Azure Monitor Agent (AMA) is the correct modern agent for Microsoft Sentinel because it unifies data collection across the entire Azure Monitor platform. It uses data collection rules (DCRs) to define exactly which data sources to collect, enabling granular filtering, multi-homing to multiple workspaces, and support for both Windows and Linux without the overhead of separate agents. AMA is the only forward-looking agent that Microsoft is actively investing in, with rich features like network isolation, Azure Arc support, and the ability to handle all log types Sentinel consumes.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.