Courseiva
easyMultiple Choice

SC-200 Practice Question: A security analyst is configuring a Microsoft…

A security analyst is configuring a Microsoft Sentinel workspace. The analyst needs to connect a third-party firewall that sends logs via Syslog and supports a common event format (CEF). Which data connector should the analyst use to ingest these logs?

⚠ Common exam trap

Many candidates confuse the older Log Analytics Agent (which also supports CEF) with the newer AMA-based connector, or mistakenly think that any Syslog connector can handle CEF without the specific parsing logic, leading them to choose a generic Syslog option not listed here.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Common Event Format (CEF) via AMA

The Common Event Format (CEF) via AMA data connector is specifically designed to ingest logs from security appliances that send Syslog messages in CEF format. CEF is an industry-standard format that allows firewalls and other devices to send structured event data, and the Azure Monitor Agent (AMA) replaces the older Log Analytics Agent for this purpose. This connector parses the CEF headers and maps the fields to the appropriate Microsoft Sentinel tables, enabling efficient threat detection and analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Common Event Format (CEF) via AMA

    Why this is correct

    The Common Event Format (CEF) via AMA connector is the correct choice for ingesting firewall logs because it is specifically designed to collect ArcSight CEF-formatted syslog messages from security appliances like firewalls, IDS/IPS, and other network devices. It uses the Azure Monitor Agent (AMA) on a Linux log forwarder, with a data collection rule (DCR) that forwards the CEF traffic to the Sentinel Log Analytics workspace. This preserves the structured CEF header and extension fields, enabling precise parsing and correlation in Sentinel analytics rules.

  • ✗

    Windows Security Events via AMA

    Why it's wrong here

    The Windows Security Events via AMA connector is incorrect for this scenario because it only collects native Windows Event Log entries—such as Security Event IDs, System, and Application logs—from Windows servers and clients. It relies on data collection rules that target Windows Event Log providers, but it does not support the syslog protocol or the CEF key-value syntax used by most firewalls. Therefore, it would not be able to parse or ingest CEF-formatted firewall logs, even though it also uses AMA.

  • ✗

    Azure Activity Log

    Why it's wrong here

    The Azure Activity Log connector is inappropriate because it ingests Azure subscription-level control-plane logs, which record events like resource creation, role assignments, and configuration changes within Microsoft Azure. Firewall logs originating from an on-premises or third-party appliance are outside the Azure platform, so this connector cannot provide any visibility into that traffic. It lacks any syslog or CEF ingestion capability and is irrelevant to network perimeter device logs.

  • ✗

    Office 365 connector

    Why it's wrong here

    The Office 365 connector is not suitable because it connects to Microsoft 365 APIs to pull auditing and activity data from productivity workloads like Exchange Online, SharePoint Online, OneDrive, and Microsoft Teams, covering user, admin, and configuration actions. It has no mechanism to receive syslog messages or parse CEF, and it is unrelated to network firewall or security appliance logs. This connector addresses SaaS platform activity, not perimeter device telemetry.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.