Courseiva

SC-200 Respond to security incidents Practice Question

Network Topology
az vm extension setresource-group MyResourceGroupvm-name MyVMname AzureMonitorWindowsAgentpublisher Microsoft.Azure.MonitorRefer to the exhibit.Azure CLI Output:```

Refer to the exhibit. An analyst runs the command to install the Azure Monitor Agent on a VM. What is the primary purpose of installing this agent in the context of security incident response?

⚠ Common exam trap

The trap is conflating the telemetry-collection agent with the endpoint-protection agent — candidates pick 'real-time malware protection' or 'vulnerability scanning' because those sound like security agent functions, but AMA only ships logs and metrics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To collect security events and performance data for analysis in Microsoft Sentinel.

The Azure Monitor Agent (AMA) is the modern replacement for the Log Analytics agent (MMA/OMS) and is used to collect security events, Windows Event Logs, Syslog, and performance counters from VMs and forward them to a Log Analytics workspace. In Microsoft Sentinel, that workspace is the data lake that powers analytics rules, hunting queries, and workbooks — so AMA's primary purpose in incident response is feeding telemetry into Sentinel for detection and investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    To collect security events and performance data for analysis in Microsoft Sentinel.

    Why this is correct

    The Azure Monitor Agent uses data collection rules to gather Windows or Linux security events and performance counters from the VM, forwarding them to the Log Analytics workspace that Microsoft Sentinel ingests. This supplies the telemetry analysts need during incident response.

  • ✗

    To integrate the VM with Microsoft Defender for Cloud.

    Why it's wrong here

    The Azure Monitor Agent collects telemetry and forwards it to Log Analytics; it does not onboard machines to Defender for Cloud, which uses its own auto-provisioning agent. It is tempting because Defender for Cloud does ingest AMA data, but that integration is a downstream consumer, not the agent's purpose.

  • ✗

    To scan the VM for vulnerabilities.

    Why it's wrong here

    Vulnerability scanning is performed by Defender for Cloud's integrated scanner (Microsoft Defender Vulnerability Management), not by the Azure Monitor Agent, which only collects and forwards event and performance data. It is tempting because scan findings surface in the same Log Analytics workspace the agent feeds.

  • ✗

    To enable real-time malware protection on the VM.

    Why it's wrong here

    Real-time malware protection comes from Microsoft Defender for Endpoint's endpoint agent, not the Azure Monitor Agent, which merely collects telemetry for analysis. It is tempting because both agents run on the same VM and their alerts appear together in Microsoft Defender portal.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.