Courseiva
easyMultiple Choice

SC-200 Practice Question: A SOC team uses Microsoft Sentinel and needs to…

A SOC team uses Microsoft Sentinel and needs to ingest custom logs from an on-premises Linux server that writes events to a local text file. The team installs the Azure Monitor Agent (AMA) on the Linux server. Which configuration step is required in Sentinel to collect the custom log file?

⚠ Common exam trap

It's easy for candidates to confuse the legacy MMA custom log configuration (which used the agent's own settings) with the modern AMA approach, which requires a DCR and a custom table — or they incorrectly assume Syslog can ingest any text file by simply mapping it to a facility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a custom table in the Log Analytics workspace and configure a Data Collection Rule (DCR) to ingest the file

Azure Monitor Agent (AMA) requires a Data Collection Rule (DCR) to define the data source (custom log file path) and the destination table in the Log Analytics workspace. Since the log is a custom text file (not syslog or a standard Windows event), you must first create a custom table (using the workspace's schema or via the 'Create custom log' wizard) and then configure the DCR to ingest the file into that table. This is the only supported method for AMA-based custom log ingestion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a custom table in the Log Analytics workspace and configure a Data Collection Rule (DCR) to ingest the file

    Why this is correct

    Custom text logs require a destination table in the Log Analytics workspace plus a Data Collection Rule that defines the file path, stream declaration and workspace target, which the Azure Monitor Agent then applies. Creating the custom table and DCR satisfies the stem's configuration requirement for ingesting the Linux server's local text file into Microsoft Sentinel.

  • ✗

    Use the Syslog connector and map the file to a facility

    Why it's wrong here

    The Syslog connector is designed to receive RFC 3164/5424 syslog messages from network devices and Linux hosts, forwarding them to a Log Analytics workspace after separating facility and severity. It cannot read an arbitrary text file from a file system, nor does it provide a mechanism to map file content to a facility. Syslog facilities are protocol-defined categories, not parsing rules for custom text.

  • ✗

    Install the Log Analytics agent (MMA) and configure Custom Logs in the agent settings

    Why it's wrong here

    Installing the Log Analytics agent (MMA) and configuring Custom Logs in the agent settings is the legacy way to ingest custom text files, but the MMA is being retired in favor of the Azure Monitor Agent (AMA). The MMA's custom log wizard supports only a basic squashing of text lines, and it does not use DCRs for transformations. Microsoft Sentinel requires the AMA with DCR-based ingestion, so using MMA's settings is an outdated and counterproductive approach.

  • ✗

    Create a scheduled analytics rule that reads the file via an API

    Why it's wrong here

    A scheduled analytics rule is a detection mechanism that runs a KQL query at a defined interval against data already stored in the Log Analytics workspace; it does not have any capability to read external files or call an API to fetch data for ingestion. Even if an API were used, you would need to push the data into the workspace (e.g., via the Log Analytics Data Collector API) before the rule can examine it. Thus, this solution would not initiate file collection at all.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.