Design solutions that align with security best practices and priorities →easyMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design solutions that align with security best practices and priorities
Your organization uses Microsoft Sentinel as its SIEM. The security team needs to detect brute-force attacks against Azure VMs by analyzing Windows Security Event logs. Which data connector should you enable?
⚠ Common exam trap
Many candidates confuse the Azure Activity log connector (which shows administrative actions like 'Deallocate VM') with guest OS-level security events, or mistakenly think Defender for Cloud provides raw Windows event logs instead of aggregated security alerts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Security Events via AMA connector
The Windows Security Events via AMA connector (D) is correct because it ingests Windows Event Logs (specifically Security logs with Event ID 4625 for failed logons) from Azure VMs into Microsoft Sentinel, enabling detection of brute-force patterns. This connector uses the Azure Monitor Agent (AMA) to collect events, which is the recommended method for modern Windows event collection in Sentinel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Office 365 connector
Why it's wrong here
The Office 365 data connector in Microsoft Sentinel collects unified audit logs for Exchange Online, SharePoint, Teams, and Azure AD sign-in events. These logs capture cloud productivity and identity activities, but they do not include Windows Security Event logs generated on endpoints. When your organization needs to analyze Windows security events, this connector cannot provide that telemetry.
- ✗
Azure Activity log connector
Why it's wrong here
The Azure Activity log connector ingests subscription-level control plane events, such as resource creation, policy changes, service health incidents, and administrative actions on Azure resources. This data is essential for auditing Azure management operations but has no visibility into OS-level security events like user logons, process creation, or file access on Windows machines. Therefore it does not satisfy the requirement for Windows security event collection.
- ✗
Microsoft Defender for Cloud connector
Why it's wrong here
The Microsoft Defender for Cloud connector brings in security alerts and recommendations across your hybrid and multicloud workloads, such as compromised resources, vulnerabilities, and threat detections. While these alerts are valuable for SOC workflows, they are aggregated findings, not raw Windows Event logs. The connector does not provide the granular Security event channel data needed for deep hunting and custom detection rules in Sentinel.
- ✓
Windows Security Events via AMA connector
Why this is correct
The Windows Security Events via Azure Monitor Agent (AMA) connector is purpose-built to stream Windows Event logs from servers and workstations directly into Microsoft Sentinel. Using a Data Collection Rule (DCR), it can collect the Security channel and other event channels, preserving the raw event details for detections and investigations. This is the correct connector when your organization must ingest Windows security events into Sentinel.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.