SC-200 Respond to security incidents Practice Question
Network Topology
Refer to the exhibit. An analyst runs the command to install the Azure Monitor Agent on a VM. What is the primary purpose of installing this agent in the context of security incident response?
⚠ Common exam trap
The trap is conflating the telemetry-collection agent with the endpoint-protection agent — candidates pick 'real-time malware protection' or 'vulnerability scanning' because those sound like security agent functions, but AMA only ships logs and metrics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To collect security events and performance data for analysis in Microsoft Sentinel.
The Azure Monitor Agent (AMA) is the modern replacement for the Log Analytics agent (MMA/OMS) and is used to collect security events, Windows Event Logs, Syslog, and performance counters from VMs and forward them to a Log Analytics workspace. In Microsoft Sentinel, that workspace is the data lake that powers analytics rules, hunting queries, and workbooks — so AMA's primary purpose in incident response is feeding telemetry into Sentinel for detection and investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
To collect security events and performance data for analysis in Microsoft Sentinel.
Why this is correct
The Azure Monitor Agent uses data collection rules to gather Windows or Linux security events and performance counters from the VM, forwarding them to the Log Analytics workspace that Microsoft Sentinel ingests. This supplies the telemetry analysts need during incident response.
- ✗
To integrate the VM with Microsoft Defender for Cloud.
Why it's wrong here
The Azure Monitor Agent collects telemetry and forwards it to Log Analytics; it does not onboard machines to Defender for Cloud, which uses its own auto-provisioning agent. It is tempting because Defender for Cloud does ingest AMA data, but that integration is a downstream consumer, not the agent's purpose.
- ✗
To scan the VM for vulnerabilities.
Why it's wrong here
Vulnerability scanning is performed by Defender for Cloud's integrated scanner (Microsoft Defender Vulnerability Management), not by the Azure Monitor Agent, which only collects and forwards event and performance data. It is tempting because scan findings surface in the same Log Analytics workspace the agent feeds.
- ✗
To enable real-time malware protection on the VM.
Why it's wrong here
Real-time malware protection comes from Microsoft Defender for Endpoint's endpoint agent, not the Azure Monitor Agent, which merely collects telemetry for analysis. It is tempting because both agents run on the same VM and their alerts appear together in Microsoft Defender portal.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.