SC-200 Manage a security operations environment Practice Question
Exhibit
{"properties": { "enabled": true, "dataTypes": { "WindowsEvent": { "state": "Enabled" }, "SecurityEvent": { "state": "Enabled" } }, "workspaceId": "<workspace-id>" } }Refer to the exhibit. You are configuring a Microsoft Sentinel Windows Security Events via AMA connector using an ARM template. After deployment, you notice that no Windows events are being ingested. The AMA agent is installed on the Windows servers. What is the most likely issue?
⚠ Common exam trap
A common mix-up: candidates assume installing the agent is sufficient for data ingestion, but Microsoft Sentinel requires the explicit link of a Data Collection Rule to the VM to define what events to collect and where to send them.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The data collection rule is not associated with the virtual machines.
The most likely issue is that the data collection rule (DCR) is not associated with the virtual machines. Even when the Azure Monitor Agent (AMA) is installed, it will not send any Windows security events to Microsoft Sentinel unless a DCR is linked to the VM. The DCR defines which events to collect and where to send them; without this association, the agent has no instructions and remains idle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The WindowsEvent and SecurityEvent data types are disabled.
Why it's wrong here
In a Microsoft Sentinel workspace, WindowsEvent and SecurityEvent are system-defined Log Analytics tables that remain enabled by default and cannot be simply switched off through a configuration toggle in the workspace settings. If these data types were truly disabled, all event data from all connected sources would be absent, but the issue here is limited to virtual machines that lack a data collection rule association. The table exists and can receive data; the actual failure is that no collection rule tells the installed Azure Monitor Agent to send those events.
- ✗
The Azure Monitor Agent is not installed on the servers.
Why it's wrong here
Per the scenario, the Azure Monitor Agent is installed on the affected servers, so the absence of event data is not due to a missing agent. An agent that is installed but not assigned to a data collection rule does run and report basic health, yet it will not collect WindowsEvent or SecurityEvent events. Because the agent is present and the symptoms point to ingestion configuration rather than agent deployment, the missing DCR association is the correct explanation.
- ✓
The data collection rule is not associated with the virtual machines.
Why this is correct
An Azure Monitor Agent only collects events once it is linked to a data collection rule (DCR), and that DCR must be explicitly associated with each virtual machine in its scope. The template likely creates the DCR object and defines the WindowsEvent and SecurityEvent data sources, but without a scope assignment or association to the target VMs, the agent receives no instruction on what to collect. This perfectly explains why the tables exist and the agent is installed, yet no Windows security events appear in Sentinel.
- ✗
The workspace ID is missing from the template.
Why it's wrong here
If the workspace ID were missing from the template, the DCR would have no destination for the collected logs and the deployment would fail during the rule validation step. The workspace ID is present in the template, so data is routed to the correct Log Analytics workspace once collection happens. The missing component is not the destination, but the connection between the DCR and the virtual machines, which is why this option is incorrect.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.